Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Internet Ingress DNAT - Odd Config Requirements?

Hello,

Seeing some I suppose unexpected behavior when configuring DNAT on Sophos Firewall (v19).

I am configuring an ingress DNAT from the internet to my Plex server. When configuring a NAT policy, I would expect to define the following:

  • Original Source: Any
  • Original Destination: Any
  • Original Service: Plex Port
  • Translated Destination: Plex Server
  • Interface Matching:
    • Inbound Interface: WAN
    • Outbound Interface: LAN

However, what I'm seeing instead is that by defining a "Outbound Interface" the NAT does not work and internet ingress to the Plex Port (service) is not open. Changing "Outbound Interface" to Any fixes this and NAT is working as expected and the port is externally exposed. After testing the following was my only working configuration:

To me this seems a bit "loose" and I would ideally specify explicit ports, hosts, and zones within the Firewall and NAT policy. Any thoughts on what I could be overlooking here?



This thread was automatically locked due to age.
Parents
  • please use the DNAT wizzard from firewall or NAT page ....


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Are you referring to creating a "Linked NAT" Firewall rule? That creates an obnoxiously open ended NAT rule, that I cant even modify:

    I see its noting that "matching criteria of the firewall... apply to the linked NAT rule", but the actual configuration of the NAT rule here is not transparent at all. I would want to actually see what is being configured if i'm using a wizard...

    Unless i'm misunderstanding something?

Reply
  • Are you referring to creating a "Linked NAT" Firewall rule? That creates an obnoxiously open ended NAT rule, that I cant even modify:

    I see its noting that "matching criteria of the firewall... apply to the linked NAT rule", but the actual configuration of the NAT rule here is not transparent at all. I would want to actually see what is being configured if i'm using a wizard...

    Unless i'm misunderstanding something?

Children
No Data