13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring a service for incoming static NATConfiguring a service for incoming static NATStatic NAT works on a port-to-host basis. Incoming packets destined for a specificpublic address and port on the External network are remapped to an address andport behind the firewall. You must configure each service separately for static NAT.Typically, static NAT is used for public services such as Web sites and e-mail that donot require authentication.Static NAT can be used only to forward connections from the outside to an internalhost. It is not possible for hosts already behind the <strong>Firebox</strong> to use the static NAT entrywhen accessing an internal server. While hosts on the External interface of the <strong>Firebox</strong>connect to the <strong>Firebox</strong> IP address and specified port (which then forwards theconnection internally), hosts on the inside of the <strong>Firebox</strong> must connect directly to theactual, internal server IP address. This is usually only a problem when DNS isinvolved. To avoid this problem, it is best to use a private DNS server (or static DNSmapping, such as /etc/hosts for UNIX machines, or an Lmhosts file for Windowsmachines) for internal hosts. This way, internal systems that try to connect to theserver by name will always get the internal IP address.Adding external IP addressesStatic NAT converts a <strong>Firebox</strong> public IP and port into specific destinations on theTrusted or Optional networks. If the <strong>Firebox</strong> has not already been assigned the publicIP address you want to use, you must designate a new public IP address using theAdd External IP dialog box. From Policy Manager:1 Select Network => Configuration. Click the External tab.2 Click Aliases.3 At the bottom of the dialog box, enter the public IP address. Click Add.4 Repeat until all external public IP addresses are added. Click OK.Setting static NAT for a serviceStatic NAT, like service-based NAT, is configured on a service-by-service basis.Because of the way static NAT functions, it is available only for services containingTCP, UDP, FTP, SMTP, or HTTP. A service containing any other protocol cannot useincoming static NAT, and the button in the service’s Properties dialog box isdisabled.1 Double-click the service icon in the Services Arena.The service’s Properties dialog box appears, displaying the Incoming tab.2 Use the Incoming drop list to select Enabled and Allowed.To use static NAT, the service must allow incoming traffic.3 Under the To list, click Add.The Add Address dialog box appears.4 Click NAT.5 Use the External IP Address drop list to select the “public” address to be used forthis service.If the public address does not appear in the drop list, click Edit to open the Add External IPAddress dialog box.66

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!