Chapter 7: Configuring Network Address Translation
106
WatchGuard Firebox System
networks behind the DVCP server. Under normal circumstances,
you should not make dynamic NAT exceptions for these networks.
6
Click the button next to the
From
box and enter the
value of the host IP address, network IP address, or
host range. Click
OK
.
7
Click
OK
to close the
Advanced NAT Settings
dialog
box.
N
OTE
Dynamic NAT exceptions allow the configuration of
exceptions to both forms of dynamic NAT. You will need to
make dynamic NAT exceptions for any 1-to-1 NAT address
that would otherwise be subject to dynamic NAT.
Using Service-Based Dynamic NAT
Using service-based dynamic NAT, you can set outgoing
dynamic NAT policy on a service-by-service basis. Service-
based NAT is most frequently used to make exceptions to a
globally applied simple dynamic NAT entry.
For example, use service-based NAT on a network with
simple NAT enabled from the trusted to the optional net-
work with a Web server on the optional network that
should not be masqueraded to the actual trusted network.
Add a service icon allowing Web access from the trusted to
the optional Web server, and disable NAT. In this configu-
ration, all Web access from the trusted network to the Web
server is made with the true source IP, and all other traffic
from trusted to optional is masqueraded.
You can also use service-based NAT instead of simple
dynamic NAT. Rather than applying NAT rules globally to
all outgoing packets, you can start from the premise that no
masquerading takes place and then selectively masquerade
a few individual services.
Summary of Contents for Firebox X1000
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System...
Page 12: ...xii WatchGuard Firebox System...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System...
Page 61: ...Cabling the Firebox User Guide 39...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System...