This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Internal NAT Rule

I know how to setup DNAT rules for external traffic getting forwarded to internal hosts. Here is what I'm looking to do. I have a DNAT rule in my firewall forwarding traffic from port 9090 to an internal servers Remote Desktop port. This works great for connecting to RDP while not connected to a VPN. The clients are using servers.domain.com:9090 to connect to the server. I would like to get an internal rule setup so when they come into the office they can still connect to servers.domain.com:9090. I'm guessing I'll need to point servers.domain.com to the internal Ip address of the firewall. I tried a few different DNAT and Full NAT configurations and was unable to get this to work correctly. Can anyone help? Also here is the configuration of the DNAT.


Traffic Source: Any
Traffic Service: 9090
Traffic Destination: External Address

NAT Mode: DNAT

Destination: Internal Server Ip
Destination Service: 3389


This thread was automatically locked due to age.
Parents
  • Try the KnowledgeBase article: Accessing Internal or DMZ Webserver from Internal Network

    Also, another common error that people make is in the Host/Network definitions they configure.  Check to make sure that the one for "Internal server IP" is not bound to a specific interface; all of the definitions you configure should be left with 'Interface: >'.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Try the KnowledgeBase article: Accessing Internal or DMZ Webserver from Internal Network

    Also, another common error that people make is in the Host/Network definitions they configure.  Check to make sure that the one for "Internal server IP" is not bound to a specific interface; all of the definitions you configure should be left with 'Interface: >'.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data