Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

firewall rules without NAT/MASQ

I'm in the phase of evaluating Sophos UTM as the standard firewall product for a large company. One thing that I stumbled upon - and which would be a show stopper - is that you can't use any firewall rules without activating masquerading. Though for many users this seems logic as they want to hide their private IP address space behind a public IP. But in my case I just want to have a firewall between two networks without doing NAT.

When setting up the UTM through the initial wizard it automatically created a MASQ rule on the WAN interface. As I didn't want that I removed that rule in the next step. Then I created firewall rules (like allow ping from any4 to any4). The hosts on the LAN side can't ping anything on the WAN side. While troubleshooting I tried many things, nothing helped until I re-entered the MASQ rule.

Is MASQ/NAT required for the firewall to work? If so, why? Is there a workaround to get firewalling without NAT (like activating MASQ but also creating a NAT excemption rule)? Firewall in bridge mode is no option as I don't need a transparent firewall but a device routing between two different IP networks.

Also I have noted that I can't add a default route the traditional way. If I create a route to 0.0.0.0/0 UTM tells me that I have to do that via the WAN interface (checkbox default gateway). I could live with that but I can think of situations where this would be counter-productive. Fun fact here: when SSHing into the UTM and issuing 'netstat -arn' I don't see the default rule. Why is that?



This thread was automatically locked due to age.
Parents
  • In fact I had situations where I needed configurations as described by you.
    In General I would say start without the wizzard and create the rules as you need them. I didn't get any Trouble if running without NAT, and yes I've created a Scenario, where I put a UTM behind some famous "fritzbox" and separated a Network behind the utm, having Firewall rules and network-Separation and Routing, all without NAT.

    One Thing I could imagine, that you got stuck, as you started to create icmp roules and tried to ping. Ping is Special for the utm, as there are checkboxes for "utm is pingable" and Forwards pings. If you don't enable those checkboxes, you won't be able to ping, even if you have icmp allow rules.

    I'd say what you want is possible with utm...

    Cheers Rolf

Reply
  • In fact I had situations where I needed configurations as described by you.
    In General I would say start without the wizzard and create the rules as you need them. I didn't get any Trouble if running without NAT, and yes I've created a Scenario, where I put a UTM behind some famous "fritzbox" and separated a Network behind the utm, having Firewall rules and network-Separation and Routing, all without NAT.

    One Thing I could imagine, that you got stuck, as you started to create icmp roules and tried to ping. Ping is Special for the utm, as there are checkboxes for "utm is pingable" and Forwards pings. If you don't enable those checkboxes, you won't be able to ping, even if you have icmp allow rules.

    I'd say what you want is possible with utm...

    Cheers Rolf

Children
No Data