24
Chapter 4
Configuring NAT Addresses
Getting Started with NAT Addresses
If there is
network address translation
(NAT) between communicating system components, the
translated IP address may have to be defined for system communications. All communications
between the StoneGate components are presented as a table in
(page 95).
You use
Location
elements to configure StoneGate components for NAT. There is a Default
Location to which all elements belong if you do not assign them a specific Location. If NAT is
applied between two system components, you must separate them into different Locations and
then add a contact address for the component that needs to be contacted.
You can define a Default contact address for contacting a component (defined in the Properties
dialog of the corresponding element). The component’s Default contact address is used in
communications when components that belong to another Location contact the component and
the component has no contact address defined for their Location.
Illustration 4.1 An Example Scenario for Using Locations
In the example scenario above, a Management Server and a Log Server manage StoneGate
components both at a company’s headquarters and in a branch office.
NAT could typically be applied at the following points:
•
The firewall at the headquarters or an external router may provide the SMC servers external
IP addresses on the Internet. The external addresses must be defined as contact addresses
so that the components at the branch offices can contact the servers across the Internet.
•
The branch office firewall or an external router may provide external addresses for the
StoneGate components at the branch office. Also in this case, the external IP addresses
must be defined as contact addresses so that the Management Server can contact the
components.
When contact addresses are needed, it may be enough to define a single new Location element,
for example, for the branch office, and to group the StoneGate components at the branch office
into the “Branch Office” Location. The same Location element could also be used to group
together StoneGate components at any other branch office when they connect to the SMC
servers at the headquarters.
Internet
Headquarters Location
Branch Office
Management/
Log Server
Analyzer
Sensor
Sensor
Analyzer
Firewall
Firewall
Intranet
Intranet
Summary of Contents for stonegate 5.2
Page 1: ...STONEGATE 5 2 INSTALLATION GUIDE INTRUSION PREVENTION SYSTEM...
Page 5: ...5 INTRODUCTION In this section Using StoneGate Documentation 7...
Page 6: ...6...
Page 12: ...12...
Page 18: ...18 Chapter 2 Planning the IPS Installation...
Page 28: ...28 Chapter 4 Configuring NAT Addresses...
Page 30: ...30...
Page 50: ...50 Chapter 6 Saving the Initial Configuration...
Page 60: ...60...
Page 72: ...72 Chapter 8 Installing the Engine on Intel Compatible Platforms...
Page 73: ...73 UPGRADING In this section Upgrading 75...
Page 74: ...74...
Page 88: ...88...