24
Chapter 4
Configuring NAT Addresses
Getting Started with NAT Addresses
If there is
network address translation
(NAT) between communicating system components, the
translated IP address may have to be defined for system communications. All communications
between the StoneGate components are presented as a table in
(page 95).
You use
Location
elements to configure StoneGate components for NAT. There is a Default
Location to which all elements belong if you do not assign them a specific Location. If NAT is
applied between two system components, you must separate them into different Locations and
then add a contact address for the component that needs to be contacted.
You can define a Default contact address for contacting a component (defined in the Properties
dialog of the corresponding element). The component’s Default contact address is used in
communications when components that belong to another Location contact the component and
the component has no contact address defined for their Location.
Illustration 4.1 An Example Scenario for Using Locations
In the example scenario above, a Management Server and a Log Server manage StoneGate
components both at a company’s headquarters and in a branch office.
NAT could typically be applied at the following points:
•
The firewall at the headquarters or an external router may provide the SMC servers external
IP addresses on the Internet. The external addresses must be defined as contact addresses
so that the components at the branch offices can contact the servers across the Internet.
•
The branch office firewall or an external router may provide external addresses for the
StoneGate components at the branch office. Also in this case, the external IP addresses
must be defined as contact addresses so that the Management Server can contact the
components.
When contact addresses are needed, it may be enough to define a single new Location element,
for example, for the branch office, and to group the StoneGate components at the branch office
into the “Branch Office” Location. The same Location element could also be used to group
together StoneGate components at any other branch office when they connect to the SMC
servers at the headquarters.
Internet
Headquarters Location
Branch Office
Management/
Log Server
Analyzer
Sensor
Sensor
Analyzer
Firewall
Firewall
Intranet
Intranet
Содержание stonegate 5.2
Страница 1: ...STONEGATE 5 2 INSTALLATION GUIDE INTRUSION PREVENTION SYSTEM...
Страница 5: ...5 INTRODUCTION In this section Using StoneGate Documentation 7...
Страница 6: ...6...
Страница 12: ...12...
Страница 18: ...18 Chapter 2 Planning the IPS Installation...
Страница 28: ...28 Chapter 4 Configuring NAT Addresses...
Страница 30: ...30...
Страница 50: ...50 Chapter 6 Saving the Initial Configuration...
Страница 59: ...59 INSTALLING SENSORS AND ANALYZERS In this section Installing the Engine on Intel Compatible Platforms 61...
Страница 60: ...60...
Страница 72: ...72 Chapter 8 Installing the Engine on Intel Compatible Platforms...
Страница 73: ...73 UPGRADING In this section Upgrading 75...
Страница 74: ...74...
Страница 88: ...88...
Страница 94: ...94 Appendix A Command Line Tools...