Solved

Watchguard x750e Configuration Issues

Posted on 2008-10-06
2
636 Views
Last Modified: 2013-11-16
Hi,

We've inhireted a network which uses the IP range 137.121.82.0 /24, we're trying to configure a new x750e using this range as the Trusted network. On the External, we have a /29 subnet of IPs to use.

The current configuration is as follows :

Eth 1 Trusted Interface : 137.121.82.230 /24
Eth 0 External Interface : This is using the PPPOE client and obtaining details via DHCP.

The problem is that traffic is not being routed externally. When configured as follows :

Eth 1 Trusted Interface : 192.168.2.1 /24
Eth 0 External Interface as above, PPPOE with IP via DHCP, traffic is being routed fine.

What could be the issue here?
0
Comment
Question by:SBSNetworks
2 Comments
 
LVL 32

Accepted Solution

by:
dpk_wal earned 500 total points
ID: 22656668
By default the dynamic NAT is only allowed from the private IP ranges, viz.:
10.0.0.0/8; 172.16.0.0/12; 192.168.0.0/16

As you have 137.121.82.0 /24 on trusted; you need to go to Policy Manager; Network->NAT; and add 137.121.82.0 /24 to be allowed as:
In Policy Manager; go to Network->NAT; click Dynamic NAT tab; click Add; add entry as:
From: 137.121.82.0 /24; to Any-External

Move up if you wish [doesn't matter]; save settings to firebox. I would like to point out to you a potential problem with this configuration, if on internet there exists some server(s) which is/are running on same IP subnet 137.121.82.0 /24; then you would not be able to access that server when behind firebox.

Please implement and update.

Thank you.
0
 

Author Closing Comment

by:SBSNetworks
ID: 31503514
Many thanks for this, this was exactly what solved the issue, you've been a great help.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question