This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ASA/Sonicwall to Sophos = Lost - NAT, Dnat, S-nat

I'm trying to figure out the language and differences.  I am coming across a variety of KB's that seem to confuse me more.

Generally my networks are similar to set up.  I have a range of 6 public IP's i usually use a 1:1 NAT on an ASA.  The default Public IP is usually just for inside clients to use for the internet or PAT. Sometimes i do need it to port forward for security camera systems etc, i think for these i can just use the business rule DNAT template and respective port forwarding.

Generally, i usually map 1 public IP to an inside host, for example Exchange.  How is this done? Specifically, i want the mapping to always be one to one, so MX records/SPF isn't an issue.  On one hand i see a KB to use the business rule to do the DNAT template and specify the public IP I want and inside server and service.  I suspect here i do not enable Rewrite address?  But this still seems to imply the server will use the outside DEFAULT IP for when it tries to go outside the network, ie send an email?  I found this KB about an SNAT to use specifically in this case, but it doesn't say i need to do the DNAT i just set up, or do I?  Is the following KB need a second step in the process as it just defines the outbound mapping for sending an email for example, as i don't see any service ports to allow for say inbound traffic?

https://community.sophos.com/kb/en-us/123294

Hopefully this makes sense...



This thread was automatically locked due to age.
Parents
  • ADH said:

    On one hand i see a KB to use the business rule to do the DNAT template and specify the public IP I want and inside server and service.  I suspect here i do not enable Rewrite address?  But this still seems to imply the server will use the outside DEFAULT IP for when it tries to go outside the network, ie send an email?  

    Correct me if I am wrong, but I believe your goal is that once you do a 1:1 mapping for a server, it should use that same Public IP while going out ?

    In that case, please try enabling 'Reflexive Rule' in the respective Business Application Rule.

    If that does not work, disable that option and create a Network Rule below for that specific server and in Routing and NAT create a Custom NAT Profile in Profile -> Network Address Translation for the respective Public IP and use that to NAT the Inside -> Outside traffic for your server.

     

    Tip: If your local network machines are unable to access the server by Public IP, also add LAN Zone in the 'Source Zone' along with WAN Zone in your Business Application Rule.

  • Hi.  Thanks for the reply.  So i would need the two rules then in order to get it going if the reflexive option doesn't work? 

Reply Children
No Data