Guest User!

You are not Sophos Staff.

Question on Destination NAT and Firewall Rule

Hi,

We are testing V18 in my LAB and I am confused with Firewall rule and Destination NAT policy. My configuration as like:

In the Firewall Rule, Why I need Destination HOST as "ANY". If I will choose a host IP in destination Host as my SSH server then this rule is not working. Is it a bug or some specific reason for the required "ANY" in the Destination HOST field?

Parents Reply
  • As mentioned in other threads, i worked quite a time with this new rule set, and my observations are:

    Working with Firewall Rules and NAT without a Linking is the best approach "for me!". 

    So basically i create my NATs based on the Needs of the setup: SNAT and DNAT (sometimes FullNAT). 

    Then creating the Firewall Rule sets based on what i want to achieve. 

    SNAT and DNAT needs firewall rules to allow the traffic, until a "automatic Firewall Rule" comes in place - Which i will not use, because of other concerns (i did not use this option ether in UTM). 

    I am using the Firewall Group feature to sort the firewalls from the beginning. Starting with a Group "DNAT" with all firewall rules, matching for my DNAT rules. Then a WAF Group, my User / zone groups. 

     

    At the moment, i agree with you, if i change a DNAT rule, i have to change the firewall rule, to match this, this is a second layer to think about in case of changing something. 

Children