McAfee UTM Firewall 4.0.4 Administration Guide
187
Firewall menu options
NAT
The firewall remains active when masquerading is disabled. If you require a finer level of control, such as
enabling or disabling masquerading for a single port, then you should use Source NAT. Refer to
Source NAT
page
.
The default configuration for the UTM Firewall appliance automatically protects your internal private IP
addresses by masquerading them to the IP address of the appliance’s Internet interface. The Masquerading
tab provides high-level controls to enable masquerading between types of network interfaces.
Note:
The displayed options apply to the firewall classes. The LAN interface options apply to all interfaces that are
configured with a LAN connection type. For NAT purposes, the Guest connection is considered a LAN interface.
Enabling masquerading
1
Click Firewall > NAT > Masquerading. The Masquerading page appears (
Figure 192
).
Figure 192 Masquerading page
2
Leave the Enable NAT from LAN/VPN interfaces to Internet interfaces checkbox selected.
Typically, this is required to allow Internet access from the LAN. If you are using a private IP address
range on your LAN (for example 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16), then you probably want
to keep this option enabled.
Note:
Disable this option only if you have publicly routable IP addresses on your LAN, which is generally not
recommended.
3
[Enabled by default] To enable masquerading for connections between any LAN interface and any DMZ
interface, select the Enable NAT from LAN/VPN interfaces to DMZ interfaces checkbox. Disable this
option only if you want to route traffic instead between the LAN/VPN to DMZ interfaces.
4
[Recommended, enabled by default] To enable masquerading for connections between any DMZ interface
and any WAN interface, select the Enable NAT from DMZ interfaces to Internet interfaces
checkbox. Disable this option only if you have publicly routable IP address on your DMZ.
5
Click Submit.
Disabling masquerading
If you disable masquerading, the UTM Firewall appliance simply routes packets instead, which might be
desired in certain environments.
1
Click Firewall > NAT > Masquerading.
2
Clear the checkboxes for the interfaces for which you want to disable masquerading.
Note:
To allow Internet access from the LAN, leave the Enable NAT from LAN/VPN interfaces to Internet
interfaces checkbox selected.
3
Click Submit.
Universal Plug and Play Gateway
The UPnP (Universal Plug and Play) Gateway allows UPnP-capable applications and devices to request port
forwarding rules to be established on demand. This allows some applications and devices that might not
operate correctly behind the NAT firewall to automatically work.
Caution:
When UPnP in enabled, any host connected to the internal network can create a port-forwarding rule on
the firewall. McAfee strongly recommends you do not enable the UPnP Gateway feature.
Summary of Contents for SG310
Page 1: ...McAfee UTM Firewall Administration Guide version 4 0 4...
Page 10: ...10 McAfee UTM Firewall 4 0 4 Administration Guide...
Page 148: ...148 McAfee UTM Firewall 4 0 4 Administration Guide Network Setup menu options SIP...
Page 372: ...372 McAfee UTM Firewall 4 0 4 Administration Guide System menu features Advanced menu...
Page 410: ...410 McAfee UTM Firewall 4 0 4 Administration Guide Index...
Page 411: ......
Page 412: ...700 2237A00...