13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CHAPTER 10Setting Up NetworkAddress TranslationNetwork address translation (NAT) hides internal network addresses from hosts onan external network. <strong>WatchGuard</strong> supports two types of NAT:• Outgoing dynamic NATHides network addresses from hosts on another network; works only on outgoingmessages.• Incoming static NATProvides port-to-host remapping of incoming IP packets destined for a publicaddress to a single internal address; works only on incoming messages.For more information on NAT, see the Network Security Handbook.What is dynamic NAT?Also known as IP masquerading or port address translation, dynamic NAT hidesnetwork addresses from hosts on another network. Hosts elsewhere only seeoutgoing packets from the <strong>Firebox</strong> itself. This feature protects the confidentiality andarchitecture of your network. Another benefit is that it enables you to conserve IPaddresses.<strong>WatchGuard</strong> implements two forms of outgoing dynamic NAT:• Simple NAT – Using host aliases or IP host and network IP addresses, the<strong>Firebox</strong> globally applies network address translation to every outgoing packet.• Service-based NAT – Configure each service individually for outgoing dynamicNAT.Machines making incoming requests over a VPN connection are allowed toaccess masqueraded hosts.<strong>User</strong> <strong>Guide</strong> 63

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!