12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring Policy Propertiesuse a 1-to-1 NAT mapping to make outgoing e-mail connections show the correct source IP address. Seethe “Working with Firewall NAT” chapter for more information on 1-to-1 NAT.1 In Policy Manager, double-click the policy icon.2 From the Connections are drop-down list, select Allowed.To use static NAT, the policy must let incoming traffic through.3 Below the To list, click Add.The Add Address dialog box appears.4 Click NAT.The Add Static NAT dialog box appears.5 From the External IP Address drop-down list, select the “public” address to use for this policy.6 Type the internal IP address.The internal IP address is the destination on the trusted network.7 If necessary, select the Set internal port to different port than service check box.You usually do not use this feature. It enables you to change the packet destination not only to a specified internalhost, but also to a different port. If you select the check box, type the different port number or use the arrow buttonsin the Internal Port box.8 Click OK to close the Add Static NAT dialog box.The static NAT route appears in the Members and Addresses list.9 Click OK to close the Add Address dialog box. Click OK to close the Properties dialog box of thepolicy.NoteSome organizations have more than one server that uses the same protocol (for example, two SMTPservers) and want to use static NAT for each server. You can do this if your Firebox is configured in routedmode and you have more than one public IP address to give to your Firebox. Set up two policies inPolicy Manager. The first policy sets up static NAT between the primary external IP address of theFirebox and your first server. The second policy sets up static NAT between a secondary IP address of theFirebox external interface and your second server.<strong>User</strong> <strong>Guide</strong> 155

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!