Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Lan - lan source nat

 how can i forward traffic from lan 1 to lan 2 with nat ?

i want all traffic (many networks ) forwarded from interface 1 (lan 1) to interface 4 (lan 2) to translate from the source network address to interface ip (interface 4)and pass to the internal network (lan 2) with translated ip

already i configured fw rules between 2 lans source any and destination any

just i want to translate all traffic to interface ip (one ip) 

thanks you



This thread was automatically locked due to age.
Parents
  • Thanks for inserting the diagram!

    If the Router in LAN 1 forwards all the traffic from behind it to port 1 on the Sophos Firewall with a source IP of 172.30.1.165, then you only need an SNAT that changes the source in packets from 172.30.1.165 to 172.20.0.1.

    Cheers - Bob
    PS If your question is about XG instead of UTM on an SG, one of us will move this thread to that community.

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • There is no nat between the router and sophos xg 430 . Traffic forwarded to sophos in origenal ip . 

    I want to translate all networks to 172.20.0.1 when forwarded from sophos to l3 switch

    And 2 lans reach each other (10.100.25.5 and all networks)

    Thank you

Reply
  • There is no nat between the router and sophos xg 430 . Traffic forwarded to sophos in origenal ip . 

    I want to translate all networks to 172.20.0.1 when forwarded from sophos to l3 switch

    And 2 lans reach each other (10.100.25.5 and all networks)

    Thank you

Children
  • Since this is a question about XG, I'll move this thread over there.

    Is all of the traffic from LAN 1 going through the XG going only to LAN IPs or does that also include traffic outbound to the internet?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Yes all traffic going only to lan  

    To server 10.100.25.5 (zone lan) not dmz zone

    No internet or public ip in my cae

    Thanks

  • Any suggestions to solve my case ?

  • Hello,
    1. SG or XG?
    2. what exactly is the problem? ...you didn't reach a network?
    Because L3 Switch and router do routing ... do you configured these devices as gateway to the networks behind them?
    Would be good to see your rules.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • hello,

    xg 430 

    simply i want to translate all coming network traffic from the router to Sophos interface IP 172.20.1 

    then forwarded to L3 switch then server 10.100.25.5

    source network 10.200.220.0, 10.35.220.0 , 10.45.220.0 ........

    destination network 10.100.25.5

    translated source network to 172.20.0.1 while source network access destination server

    thanks

  • NAT Looks good so far.
    You need a Firewall rule allowing this traffic.
    (try Any to 10.100.25.5 first)

    PS: Your interface ip isn't 172.20.0.1/32 (like in your picture) but 172.20.0.1/24 ...!?

    Enable logging within firewall-rules and Check logviewer. Set free-text-search-filter to 10.100.25.5

    please show us your "source network 10.200.220.0, 10.35.220.0 , 10.45.220.0" - definitions ... or try "any" for a short time instead

    L3-Switch and Router use Firewall as default gateway?


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • dear ,

    (try Any to 10.100.25.5 first) ... done

    PS: Your interface IP isn't 172.20.0.1/32 (like in your picture) but 172.20.0.1/24 ...!? you're right my interface port 1 

    and IP 172.30.1.66

    L3-Switch and Router use Firewall as the default gateway? the default gateway for network  10.100.25.0/24 on different firewall connected between the L3 switch and server.

    so tomorrow I will test and inform you
    thanks alot

  • PS: Your interface IP isn't 172.20.0.1/32 (like in your picture) but 172.20.0.1/24 ...!? you're right my interface port 1 

    and IP 172.30.1.66

    yes ... but at Port 4 you paint a 32 Bit network-mask ... i think you have /24 here ...


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • 172.30.1.166/30 

    sir 

    just i have a question plz

    is xg 430 support translates all networks hosts (10.200.220.1,.....) to a single IP or interface IP and forwards traffic to port 1 

    (10.100.25.5) ?

    which means server 10.100.25.5 accessed just by one IP from all networks 

  • Yes. This is how internet access works ... mostly.

    There may be an error in your NAT definition... a screenshot would be helpful.

    Here you can see my "Masquerade all at one interface" rule


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.