Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Nat Policy SonicWall TZ170

Posted on 2009-05-13
3
Medium Priority
?
1,771 Views
Last Modified: 2013-11-16
SonicWall TZ170
OS- Sonic OS Enhanced 2.1.02
Three zones on the firewall: WAN- 192.168.1.1, LAN- 172.16.1.1, OPT (DMZ)- 10.10.10.1

I am trying to set up a NAT policy from the DMZ to the LAN zone and back.  I want machine A (10.10.10.2) connected to the OPT port to look like it is coming from the LAN Port (172.16.1.1) when it contacts machine b (172.16.1.2) on the LAN using ssh.

[10.10.10.2] >>> [10.10.10.1 OPT-SONICWALL-LAN 172.16.1.1] >>> [172.16.1.2]

In the left margin I went to NETWORK>NAT POLICIES> ADD
Original Source: 10.10.10.2
Translated Source: 172.16.1.1
Original Destination:  10.10.10.1
Translated Destination: 172.16.1.2
Original Service: SSH
Translated Service: SSH
Inbound Interface: ANY
Outbound Interface: ANY

Original Source: 172.16.1.2
Translated Source: 10.10.10.1
Original Destination:  172.16.1.1
Translated Destination: 10.10.10.2
Original Service: SSH
Translated Service: SSH
Inbound Interface: ANY
Outbound Interface: ANY

It takes the policy without error and looks like it should work.

I also setup firewall rules to allow the traffic from the DMZ to the LAN.

I try to ssh from 10.10.10.2 to 172.16.1.2 and the outgoing packet makes it out of the SonicWall, but it has a source address of 10.10.10.2.   The sonicwall is simply passing the packet through and not changing the source address to 172.16.1.1.  So when 172.16.1.2 gets it it doesn't know what to do with it.  No matter what I try the packet passes through the SonicWall with out it being NATed to 172.16.1.1.

I'm looking for any suggestions on this.  I've tried everything I can think of.    
0
Comment
Question by:credog
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 6

Accepted Solution

by:
KevinCovert earned 1500 total points
ID: 24376892
Try using a translated IP that is not your gateway IP.  

orig        <<>> translated
10.x.x.2.<<>>172.x.x.3

172.x.x.2 <<>> 10.x.x.3

I would give that a shot first.
0
 
LVL 6

Expert Comment

by:KevinCovert
ID: 24437130
How are you doing on this issue?
0
 

Author Closing Comment

by:credog
ID: 31581024
Sorry it took so long to get back to this issue.  We decided to go another way, so I was unable to try your solution.  Thank you for responding.
0

Featured Post

Are You Ready for GDPR?

With the GDPR deadline set for May 25, 2018, many organizations are ill-prepared due to uncertainty about the criteria for compliance. According to a recent WatchGuard survey, a staggering 37% of respondents don't even know if their organization needs to comply with GDPR. Do you?

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
In this video, Percona Solution Engineer Rick Golba discuss how (and why) you implement high availability in a database environment. To discuss how Percona Consulting can help with your design and architecture needs for your database and infrastr…
Suggested Courses

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question