Got it

Understand Firewall NAT Server & Source NAT Using the CLI - In Practice - Part 2

Latest reply: Jan 21, 2022 09:00:35 603 24 21 0 0

Understand Firewall NAT Server & Source NAT Using the CLI - In Practice

Hello guys!


Today, I would like to present an introduction to Firewall NAT Server & Source NAT in practice.


About This Experiment


After NAT is configured on the firewall connecting an intranet to the Internet, multiple users on the intranet can access the Internet at the same time by using a small number of public IP addresses. In addition, users on the Internet can access the intranet server through specific IP addresses.

Ps: All addresses used in the example are false and used only in a lab environment for study purposes.


Configuration Roadmap


1. Configure IP addresses for interfaces and add the interfaces to security zones. Configure a security policy to permit packets from the Untrust zone to the DMZ.

2. Configure NAT Server.

3. Create a NAT address pool.

4. Configure a NAT policy.


Configuration Procedure on the CLI


Step 1 Complete the configuration of the upstream and downstream service interfaces on the USG. Configure IP addresses for the interfaces and add the interfaces to security zones. (Omitted)


Step 2 Configure a security policy to filter the packets transmitted between security zones.


1


Step 3 Configure NAT Server.


IP


Step 4 Configure a NAT address pool.


3


Step 5 Configure NAT ALG for the DMZ-Untrust interzone to ensure that the intranet server can provide the FTP service for Internet users. This step can be omitted because NAT ALG is enabled globally by default.


4


Step 6 Create a NAT policy for the DMZ-Untrust interzone, define the range of source IP addresses for NAT, and bind the NAT policy to NAT address pool 2.


IP


Verification


Checking the NAT Server Information


Run the display nat server command to check the NAT Server information.


IP


With that our practical example was completed.


Cheers,

You can learn more about the source NAT at Source NAT types of firewall.

View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Jan 5, 2022 18:29:53 (3) (0)
thanks master  
Good share
View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Jan 5, 2022 18:30:07 (1) (0)
tks  

You can learn more about the source NAT at Source NAT types of firewall.

View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Jan 5, 2022 18:29:53 (3) (0)
thanks master  
Good share
View more
  • x
  • convention:

Very informative and useful post
View more
  • x
  • convention:

Thanks for sharing
View more
  • x
  • convention:

Diego.Silva
MVE Author Created Jan 10, 2022 13:51:25

very good post! thank you for sharing!
View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Jan 10, 2022 18:18:09 (1) (0)
thank you  
Vlada85
MVE Author Created Jan 10, 2022 15:19:55

Thank you
View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Jan 10, 2022 18:18:23 (0) (0)
thank you friend  
Excellent post. Thanks for sharing
View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Jan 14, 2022 17:00:20 (0) (0)
thank you dear  
Awesome, thank you for sharing!
View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Jan 14, 2022 17:00:42 (0) (0)
thank you bro  
12
Back to list

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.