Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Subnet not NATED

I have got the following topology:

PC <----> ROUTER <---->  MPLS CIRCUIT <-----> XG FIREWALL <----> INTERNET

I have connect my PC to the Internet. I have put a NAT rule in the router. The firewall also has a NAT rule. Then, it works fine.

But when I deleted the NAT rule in the router then I have lost theconnectivity to the Internet. I couldnt reach the internet gateway IP. I could reach the WAN interface of the Sophos firewall.

I have to avoid NAT in the router because I need to keep the IP in order to apply web filtering only to that IP address behind of the router.



This thread was automatically locked due to age.
Parents
  • Can you show us the NAT-Rule from firewall? Check firewall-live-log and compare to your NAT-Rule. I think there is a mismatch.

    Why you don't use "masquerading"?

  • Hello Dirk,

    I am using masquerade (MASQ) in the Firewall (Sophos) , however I can't reach the ISP router interface from PC (behind the router Mikrotik in the remote location into my LAN). When I do both: SCRNAT in the router (remote location into my LAN) and also MASQ in the Firewall, then I can reach the Internet from PC and also from mikrotik router.

    When I deleted the SRCNAT in the mikrotik router then I only could reach internet from mikrotik but not from PC. However, I am keeping the masquerade in the Firewall.

Reply
  • Hello Dirk,

    I am using masquerade (MASQ) in the Firewall (Sophos) , however I can't reach the ISP router interface from PC (behind the router Mikrotik in the remote location into my LAN). When I do both: SCRNAT in the router (remote location into my LAN) and also MASQ in the Firewall, then I can reach the Internet from PC and also from mikrotik router.

    When I deleted the SRCNAT in the mikrotik router then I only could reach internet from mikrotik but not from PC. However, I am keeping the masquerade in the Firewall.

Children