Solved

Interface NAT mode on a SSG / ScreenOS 6.X

Posted on 2011-02-10
5
1,263 Views
Last Modified: 2013-11-16

I don't usually use interface NAT mode so I need to clarify a question.  I don't have access to a SSG right now so I hoping some can help me out.

Scenario: I have a SSG device with the three zones defined (Untrust, Trust, and DMZ) and the DMZ interface (ethernet 0/3) is in NAT mode.

From reading the documentation it appears when traffic is initiated from the Trust zone and traverses the SSG and headed out either the Untrust or DMZ zone interfaces the source-IP will be src-NAT'd to the egress interface.

What is not clear is suppose you have a host in the DMZ that initiates traffic to a host in the Trust zone.  Assuming they are no policy based NAT statements, will the traffic be NAT'd?  The documentation in my opinion just isn't clear on this circumstance.

Thanks....
0
Comment
Question by:norgetek
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
5 Comments
 
LVL 18

Expert Comment

by:deimark
ID: 34866916
Interface nat occurs in the following circumstances

From trust to untrust
From DMZ to untrust

All other traffic will NOT be natted unless specifically defined in a policy

So for traffic from DMZ to trust, interface NAT does NOT occur

HTH
0
 
LVL 4

Author Comment

by:norgetek
ID: 34867778
Typed to fast when I made the post:

This is the scenario I meant to describe:

I have a SSG device with the three zones defined (Untrust, Trust, and DMZ) and the Trust interface (ethernet 0/2) is in NAT mode.
0
 
LVL 18

Accepted Solution

by:
deimark earned 250 total points
ID: 34868960
Then the above still applies

Interface nat occurs in the following circumstances

From trust to untrust
From DMZ to untrust

If you want to nat any other kind of traffic, then policy nat must be used.

As a side note, when I install screenos devices for customers I always turn off interface nat and use policy nat to control the natting done,  As well as making sure the exact type of nat is happening in the right place, we see a nice little blue tick in the policy screen to tell me nat is being done in that rule, but interface nat is there for those that want it
0
 
LVL 70

Expert Comment

by:Qlemo
ID: 35106964
This question has been classified as abandoned and is being closed as part of the Cleanup Program. See my comment at the end of the question for more details.
0

Featured Post

Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as the high-speed power of the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
In this video, viewers are given an introduction to using the Windows 10 Snipping Tool, how to quickly locate it when it's needed and also how make it always available with a single click of a mouse button, by pinning it to the Desktop Task Bar. Int…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question