Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DNAT

I have some wan address and some server in DMZ, how I can DNAT the request FROM DMZ server to public ip on WAN without MASQ ?

Example WAN IP ADRESS 77.77.77.1 -> DMZ Adress 192.168.38.1 

request from 192.168.38.200 to 77.77.77.1 how I can DNAT to 192.168.38.1 ?

If I use MASQ the server 192.168.38.1 logs acess from out interface of firewall (ex.192.168.38.254) instead of ip address of 192.168.38.200

thanks



This thread was automatically locked due to age.
Parents Reply
  • I have already tried this, but from inside WAN address (assigned to sophos) only work (strangely) if I enable MASQ on the rule coming from DMZ or LAN.

    This is an anomaly on how the rule must be create on xg firewall, I use currently other type of firewall (Fortigate, PFSense, Untangle...ecc...) without problems.

Children