Solved

one-to-one nat

Posted on 2004-04-28
4
315 Views
Last Modified: 2010-05-18
From what I understand by default sonic walls lock down all port unless specified otherwise.  However I have been told that when I enable one-to-one nat this is not true for the public IPs I am forwarding.  Is this the case?  And if so when I start shutting down ports should I shut down the ports for the publics IPs or for the private IPs the Public IPs are being forwarded to or both?  Thanks.
0
Comment
Question by:srawtvl
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 23

Expert Comment

by:Tim Holman
ID: 10940729
When you enable one-to-one NAT, you will also need to create a rule to allow traffic to hit those addresses.

For example, mail server public IP 20.20.20.20, private IP 192.168.0.1 -

You would enable one-to-one NAT to translate 20.20.20.20 to 192.168.0.1.
You would then create a firewall rule to allow port 25 to hit 20.20.20.20.

You do NOT need any more than this.  Everything else is implicitly denied, and traffic that is translated (as long as it's port 25) will be routed through to your private address without any additional rules.
0
 

Author Comment

by:srawtvl
ID: 10951550
This is not true.  I set up a bsd server behind the firewall and pointed a public IP to the private IP addy the bsd box is on.  I did not change any permissions on the firewall.  I am able to SSH to the bsd box from outside our network.  Can someone tell me if I should block ports to the public IP in this case or the private or both? and can someone tell me what sonic wall means by default in their services list?  is it the same as any on a cisco router?
0
 

Author Comment

by:srawtvl
ID: 10952545
OK so I answered my own question.  For anyone else who may need to know heres the deal.

Sonic wall explicitely allows everything.  You have to go in and remove the rules for the service "default" expect for where the source is LAN.

If you are using one-to-one nat you have to then go in and allow the services you need to the PRIVATE addresses.

And default means everything...how intuitive
0
 
LVL 23

Accepted Solution

by:
Tim Holman earned 500 total points
ID: 10958198
..yet another firewall vendor doing things slightly different to confuse us !  :)
0

Featured Post

Retailers - Is your network secure?

With the prevalence of social media & networking tools, for retailers, reputation is critical. Have you considered the impact your network security could have in your customer's experience? Learn more in our Retail Security Resource Kit Today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Come and listen to Percona CEO Peter Zaitsev discuss what’s new in Percona open source software, including Percona Server for MySQL (https://www.percona.com/software/mysql-database/percona-server) and MongoDB (https://www.percona.com/software/mongo-…
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question