Watchguard Firebox X5-W Guía de usuario Pagina 114

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 234
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 113
Managing Network Traffic
98 Firebox X Edge e-Series
1-to-1 NAT
You can use 1-to-1 NAT to map a secondary external IP address to the server behind the Edge. You do
not have to change the IP address of your internal server. When you enable 1-to-1 NAT, the Firebox X
Edge changes all outgoing packets sent from one private IP address to a public IP address different from
the Edges primary external IP address.
Static NAT
Static NAT is usually known as “port forwarding.” When you use static NAT, you use the primary external
IP address of your Firebox X Edge e-Series instead of the IP address of a public server. You could do this
because you want to, or because your public server does not have a public IP address.. Traffic to that
internal server is sent to a port on the public IP address of your Firebox X Edge. The Edge uses Static NAT
to send the traffic on that port to the server behind the Edge.
For example, you can put your SMTP e-mail server behind the Edge with a private IP address and config-
ure static NAT in your SMTP policy. The Firebox X Edge receives connections on port 25 and makes sure
that any SMTP traffic is sent to the real SMTP server behind the Edge.
You configure Static NAT with incoming firewall services. For more information, see “Configuring com-
mon services for incoming traffic” on page 79.
NAT behavior
When you configure NAT:
1 Each interface on the Firebox X Edge e-Series must use a different TCP subnet.
2 There can only be one trusted network, one optional network, and one external network.
You can use a router to connect more subnets to these networks. For more information, see “Connecting the Edge to
more than four devices” on page 15.
3 The Edge always uses Dynamic NAT for traffic going from the trusted or optional networks to the
external network.
4 Dynamic NAT is not applied to BOVPN or MUVPN traffic.
Secondary IP addresses
You can assign eight public IP addresses to the primary external interface (WAN1). These addresses are
used for 1-to-1 NAT.
When you configure secondary IP addresses on the external network:
1 The primary IP address must be a static IP address.
The first IP address is the primary IP address.
2 All secondary IP addresses must be on the same external subnet as the primary IP address.
3 You cannot configure multiple IP addresses for the WAN2 failover interface.
The WAN2 interface is reserved for WAN failover, and your failover IP address must be on a different subnet.
Vista de pagina 113
1 2 ... 109 110 111 112 113 114 115 116 117 118 119 ... 233 234

Comentarios a estos manuales

Sin comentarios