This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Flat network setup

This is a pretty simple question and I am hoping there is a simple answer.  We have an environment where we have a public class 3 network assigned to devices on our LAN.There is no NAT whatsoever.  The firewall should just route traffic to the LAN IP addresses.

For instance:

WAN IP - x.x.112.23

LAN IP - x.x.x.1  (public ip range 1 - 254)

When someone tries to reach a device on the 1-254 range, it just routes through the firewall to those devices.  We are replacing the existing firewall with an XG and I would like to keep the same configuration. 

My questions is, would I need to add an alias for every device on our LAN and setup DNAT rules for every device?  Or would the firewall just route the traffic in the same way as the old firewall.  If we had to do the Alias/DNAT route, I am not sure how that would work without using NAT IP addresses for the devices on the LAN.

Maybe I am over-thinking this. Any help would be appreciated.



This thread was automatically locked due to age.
Parents
  • Hey  

    Welcome to Sophos Community!

    For an architectural network planning question like this, I would advise bringing this to your Sophos Partner/Reseller that you are purchasing your firewall from. They would be able to get you in touch with a Sales Engineer to provide suggestions and a proof of concept for your specific network setup. 

    I apologize for not providing a more specific answer, but a scope of this query that involves a migration would best be suited for hands-on assistance and follow up.

    Regards,

Reply
  • Hey  

    Welcome to Sophos Community!

    For an architectural network planning question like this, I would advise bringing this to your Sophos Partner/Reseller that you are purchasing your firewall from. They would be able to get you in touch with a Sales Engineer to provide suggestions and a proof of concept for your specific network setup. 

    I apologize for not providing a more specific answer, but a scope of this query that involves a migration would best be suited for hands-on assistance and follow up.

    Regards,

Children
No Data