Solved

Watchguard X700 Firewall - Configure Static NAT or Complete DMZ

Posted on 2010-09-20
2
1,104 Views
Last Modified: 2012-05-10
Hi, I've got a voip application which needs either a Static NAT or a complete DMZ. Firewall is an old Watchguard X700 Firewall.

Can someone post a step by step to get the box to do DMZ to an internal machine. Statically map an external address to an internal for example.

We've done this as many times but it's just not working.

Thanks
0
Comment
Question by:binele
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 32

Accepted Solution

by:
dpk_wal earned 500 total points
ID: 33730864
If you have a public IP which you would like to dedicate for the VoIP device so that WG would not do any
PAT, then configure 1-1 NAT as below:
http://watchguard.custhelp.com/app/answers/detail/a_id/1545/kw/1-1%20NAT%20configuration/session/L3NpZC9pTjd0dENhaw%3D%3D

Also, ensure that the public IP you have selected for 1-1 NAT was not previously added for static NAT forwarding by adding under external aliases:
http://watchguard.custhelp.com/app/answers/detail/a_id/1318/session/L3NpZC9pTjd0dENhaw%3D%3D

Finally create a service to allow traffic from external host/subnet to this 1-1 NAT public IP [or use ANY for testing purposes and then narrow down the service to fewer ports/protocols]; explained in the first article.

Please update.

Thank you.
0
 

Author Comment

by:binele
ID: 33734061
Thank you. This was spot on.
0

Featured Post

[Webinar] Code, Load, and Grow

Managing multiple websites, servers, applications, and security on a daily basis? Join us for a webinar on May 25th to learn how to simplify administration and management of virtual hosts for IT admins, create a secure environment, and deploy code more effectively and frequently.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question