About NAT
Firebox Vclass User Guide
199
You can apply one-to-one, many-to-many, or subnet-to-
subnet static NAT policies to qualifying traffic. All types of
static NAT action are described in this section.
Before you proceed, you should be aware of the following
constraints on static NAT policies as applied by a Firebox
Vclass appliance:
•
Static NAT policies are limited in that they can
translate only IP addresses.
•
Static NAT policies do not support VIP load balancing.
•
If a VPN policy includes a static NAT action, the peer
tunnel IP address cited in the IPSec action must be the
primary interface 0 IP address, not any of the
secondary addresses assigned to this interface.
•
If IP addresses that are to be mapped are not in the
same subnet as interface 1 (Public), proper routing
must be configured to ensure that traffic to these
mapped IP addresses is routed to interface 1 of this
appliance.
Dynamic NAT
If you have a number of employees or other private net-
work users whose client computers have been assigned IP
addresses for internal use, you can grant all of them full
access to the Internet using dynamic Network Address
Translation (
dynamic NAT
).
You can insert policies into a Firebox Vclass security appli-
ance that apply dynamic NAT to qualified traffic in the fol-
lowing ways:
Public IP
This action substitutes the IP address of the 0
(Public)
interface on the appliance for all internal
use IP addresses. This allows internal users to gain
one-way access to the Internet using the IP address
of the appliance’s Public interface.
Summary of Contents for Firebox V10
Page 1: ...WatchGuard Firebox Vclass User Guide Vcontroller 5 0 ...
Page 32: ...xxxii Vcontroller ...
Page 40: ...CHAPTER 1 Introduction 8 Vcontroller ...
Page 52: ...CHAPTER 2 Service and Support 20 Vcontroller ...
Page 70: ...CHAPTER 3 Getting Started 38 Vcontroller ...
Page 110: ...CHAPTER 4 Firebox Vclass Basics 78 Vcontroller ...
Page 190: ...CHAPTER 7 Using Account Manager 158 Vcontroller ...
Page 268: ...CHAPTER 9 Security Policy Examples 236 Vcontroller ...
Page 410: ...CHAPTER 14 Monitoring the Firebox Vclass 378 Vcontroller ...
Page 456: ...CHAPTER 18 Using the Diagnostics CLI Feature 424 Vcontroller ...