Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Using WAN Alias IP for specific hosts in LAN

Good evening everyone,


I would need to exit some servers with specific IPs connected to interface 3 via dedicated WAN IP Aliases.

Details:

l'IP pubblico "alias" 5.88.135.10 #port2:3, Host 10.90.90.20

Firewall XG116 firmware version 18

Best regards

Francesco



This thread was automatically locked due to age.
Parents
  • You need to combine SD-WAN PBR and NAT for this scenario. 
    So create a SD-WAN Policy based route for the traffic and select Port2 or Port3. 

    Then create a NAT Rule, which uses the needed Source IP for the specific traffic. 

  • LuCar thank you very much for the quick reply.

    but if I were to configure multiple hosts to multiple public IP?

    For example:

    SERVER:            10.90.90.20                   PUBLIC IP:                  5.88.135.10  

    SERVER:            10.90.90.21                   PUBLIC IP:                  5.88.135.11  

    SERVER:            10.90.90.22                   PUBLIC IP:                  5.88.135.12  

    SERVER:            10.90.90.23                   PUBLIC IP:                  5.88.135.13

    How should I set up SD-WAN? what should I set on origin and destination?

    Also I need a firewall rule for each server to perform port forwarding of port 443. (rule already done)

    This automatically creates 3 NAT rules:

    Thanks so much again for the support.

    Francesco

  • If those Server should communicate throught just one interface, you only need one SD-WAN Rule: All Servers, to ANY (or the internetv4 object of this KB https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/129512/xml-import-for-internetv4-objects), using WAN Interface 1. 

    Then you need per Server one NAT Rule, which uses server 1 LAN Ip and SNAT it to WAN IP 1. 

Reply Children