This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

NAT reflection DMZ to LAN

Hi,

i would like to do a  "NAT reflection" in XG but from a DMZ (actually a guest WLAN) to LAN using the public IP, forwarding back inside to the LAN

I have seen how LAN back into LAN is explained in https://community.sophos.com/products/xg-firewall/f/network-and-routing/73239/nat-reflection

Can it be done?

Thanks



This thread was automatically locked due to age.
Parents
  • Hi  

    Yes, you would be able to configure this NAT reflection (Hairpin) rule as per that community thread.

    In your situation:

    Create business application rule (DNAT/Full NAT/Load Balancing)

    • Source Zone: DMZ
    • Source Network: Any
    • Destination host/network: Public IP
    • Services: Define the services used
    • Protected Server: LAN IP of server
    • Protected Zone: LAN
    • Rewrite Source Address (masquerading): Enabled
    • Use outbound IP: LAN interface GW IP
    • Log Firewall Traffic: Enabled

    Please let me know if you had any issues.

    I will follow up with our KB team in regards to publishing an article regarding this.

  • Thanks for the answer!

    When i choose "Rewrite Source Address (masquerading): Enabled" i also have to choose "use outbound address" what to choose there?

    Do i create and use the address of the fw-interface for this network?   

    Since it is a WLAN (a wlan-router involved), is there a problem with the tcp connections (port 443) going back and forth?

    XG330 SFOS 17.1.3 MR-3

Reply
  • Thanks for the answer!

    When i choose "Rewrite Source Address (masquerading): Enabled" i also have to choose "use outbound address" what to choose there?

    Do i create and use the address of the fw-interface for this network?   

    Since it is a WLAN (a wlan-router involved), is there a problem with the tcp connections (port 443) going back and forth?

    XG330 SFOS 17.1.3 MR-3

Children