Chapter 7: Configuring Network Address Translation
102
WatchGuard Firebox System
static NAT. Typically, static NAT is used for public
services that do not require authentication such as
Web sites and email.
1-to-1 NAT
The Firebox uses private and public IP ranges that
you specify, rather than the ranges assigned to the
Firebox interfaces during configuration.
Choosing which type of NAT to perform depends on the
underlying problem being solved, such as those regarding
address security or preservation of public IP addresses. For
more information on NAT, see the following collection of
FAQs:
https://support.watchguard.com/advancedfaqs/nat_main.asp
Dynamic NAT
Dynamic NAT is the most commonly used form of NAT. It
works by translating the source IP address of outbound
sessions (those originating on the internal side of the Fire-
box) to the one public IP address of the Firebox. Hosts else-
where only see outgoing packets from the Firebox itself.
This type of NAT is most commonly used to conserve IP
addresses. It allows multiple computers to access the Inter-
net by sharing one public IP address. Even if the number of
public IP addresses is not a concern, dynamic NAT pro-
vides extra security for internal hosts that use the Internet
by allowing them to use non-routable addresses.
The WatchGuard Firebox System implements two forms of
outgoing dynamic NAT:
Simple dynamic NAT
Using host aliases or host and network IP
addresses, the Firebox globally applies network
address translation to every outgoing packet. This
is the most commonly used type of NAT.
Summary of Contents for Firebox X10E
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Page 12: ...xii WatchGuard Firebox System ...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Page 61: ...Cabling the Firebox User Guide 39 ...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...