Chapter 7: Configuring Network Address Translation
110
WatchGuard Firebox System
Using 1-to-1 NAT
1-to-1 NAT uses a global NAT policy that rewrites and
redirects packets sent to one range of addresses to a com-
pletely different range of addresses. This address conver-
sion works in both directions. You can configure any
number of 1-to-1 NAT addresses.
A common reason to use 1-to-1 NAT is to map public IP
addresses to internal servers without needing to renumber
those servers. 1-to-1 NAT is also used for VPNs in which
the remote network’s IP addressing scheme conflicts with
the local scheme. By translating the local network to a
range that is not in conflict with the other end, both sides
can communicate. For more information on 1-to-1 NAT, see
the following FAQ:
https://support.watchguard.com/advancedfaqs/
nat_onetoone.asp
Each NAT policy contains four configurable pieces of infor-
mation:
•
The interface (External, Trusted, Optional, IPSec)
•
The public IP address
•
The internal IP address
•
The number of hosts to remap
The NAT base plus the range defines the NAT region while
the real base plus the range defines the hidden or for-
warded region.
For instance, the following policy:
210.199.6.0–192.168.69.0:255 (NAT base to real base
range)
means that all traffic addressed to hosts between
210.199.6.0 and 210.199.6.255 is forwarded to the corre-
sponding IP address between 192.168.69.0 and
192.168.69.255.
Summary of Contents for Firebox X10E
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Page 12: ...xii WatchGuard Firebox System ...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Page 61: ...Cabling the Firebox User Guide 39 ...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...