Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Nat Policy SonicWall TZ170

Posted on 2009-05-13
3
Medium Priority
?
1,776 Views
Last Modified: 2013-11-16
SonicWall TZ170
OS- Sonic OS Enhanced 2.1.02
Three zones on the firewall: WAN- 192.168.1.1, LAN- 172.16.1.1, OPT (DMZ)- 10.10.10.1

I am trying to set up a NAT policy from the DMZ to the LAN zone and back.  I want machine A (10.10.10.2) connected to the OPT port to look like it is coming from the LAN Port (172.16.1.1) when it contacts machine b (172.16.1.2) on the LAN using ssh.

[10.10.10.2] >>> [10.10.10.1 OPT-SONICWALL-LAN 172.16.1.1] >>> [172.16.1.2]

In the left margin I went to NETWORK>NAT POLICIES> ADD
Original Source: 10.10.10.2
Translated Source: 172.16.1.1
Original Destination:  10.10.10.1
Translated Destination: 172.16.1.2
Original Service: SSH
Translated Service: SSH
Inbound Interface: ANY
Outbound Interface: ANY

Original Source: 172.16.1.2
Translated Source: 10.10.10.1
Original Destination:  172.16.1.1
Translated Destination: 10.10.10.2
Original Service: SSH
Translated Service: SSH
Inbound Interface: ANY
Outbound Interface: ANY

It takes the policy without error and looks like it should work.

I also setup firewall rules to allow the traffic from the DMZ to the LAN.

I try to ssh from 10.10.10.2 to 172.16.1.2 and the outgoing packet makes it out of the SonicWall, but it has a source address of 10.10.10.2.   The sonicwall is simply passing the packet through and not changing the source address to 172.16.1.1.  So when 172.16.1.2 gets it it doesn't know what to do with it.  No matter what I try the packet passes through the SonicWall with out it being NATed to 172.16.1.1.

I'm looking for any suggestions on this.  I've tried everything I can think of.    
0
Comment
Question by:credog
  • 2
3 Comments
 
LVL 6

Accepted Solution

by:
KevinCovert earned 1500 total points
ID: 24376892
Try using a translated IP that is not your gateway IP.  

orig        <<>> translated
10.x.x.2.<<>>172.x.x.3

172.x.x.2 <<>> 10.x.x.3

I would give that a shot first.
0
 
LVL 6

Expert Comment

by:KevinCovert
ID: 24437130
How are you doing on this issue?
0
 

Author Closing Comment

by:credog
ID: 31581024
Sorry it took so long to get back to this issue.  We decided to go another way, so I was unable to try your solution.  Thank you for responding.
0

Featured Post

New Tabletop Appliances Blow Competitors Away!

WatchGuard’s new T15, T35 and T55 tabletop UTMs provide the highest-performing security inspection in their class, allowing users at small offices, home offices and distributed enterprises to experience blazing-fast Internet speeds without sacrificing enterprise-grade security.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
Integration Management Part 2
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…
Suggested Courses

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question