Solved

Sonicwall Change Outbound NAT for Server

Posted on 2014-11-01
16
147 Views
Last Modified: 2014-12-25
Hey guys,

I have a Sonicwall NSA2400. Now one server, i opened a few ports to it and its working fine from the Outside. But when this server goes to the Internet, its going out with the Firewall's outside IP, i need to change this to a different IP. How would i do that on this firewall?
0
Comment
Question by:Cobra25
  • 6
  • 6
  • 2
  • +1
16 Comments
 

Expert Comment

by:bNetworked
Comment Utility
What IP do you need to change it to and why?  Normal operation for a firewall is to use NAT (network address translation) to make everything look like it's coming from the internet side IP to protect all the computers behind it from being open and vulnerable to attack.  Depending on what you want to do, it may be possible to do with the Sonicwall using virtual interfaces or DMZ.  I think that we need more information in order to address this.
0
 
LVL 38

Expert Comment

by:Aaron Tomosky
Comment Utility
Yes you can do this. First make an address object for the ip you want it to be, Then make a nat rule for that server where translated from is that address object
0
 
LVL 38

Expert Comment

by:Aaron Tomosky
Comment Utility
Alternatively I suggest you use the public server wizard instead of doing this manually. Then edit the service group to have the services you want.
0
 
LVL 4

Author Comment

by:Cobra25
Comment Utility
So its for my mail server.
Internal ip -- 192.168.60.10
Outside Ip: x.x.x.55
Firewall outside ip: x.x.x.60

So from the outside to in using the 55 address it works fine. When the mail server goes out to the internet/sends email, it goes out as the .60 which is causing mail to get blocked because the rdns/forward dns do not match.
0
 
LVL 4

Author Comment

by:Cobra25
Comment Utility
Any thoughts guys?
0
 
LVL 38

Expert Comment

by:Aaron Tomosky
Comment Utility
Is .60 the default for all traffic?

I've already said how to do this, Just make a nat rule from the exchange host to the Internet (X1 probably) translated source .55.
http://help.mysonicwall.com/sw/eng/305/ui2/23100/Network/Add_NAT_Policy.htm
0
 
LVL 4

Author Comment

by:Cobra25
Comment Utility
Aaron - thanks for the response.

Yes , .60 is the default.

Do i make a new rule or can i modify the existing NAT rule?

Right now my NAT Policy for this server is:
Original Source: Mail Server Private
Translated Source: Mail Server Public
Original Destination: Any
Translated Destination: Original
Original Service: Mail Server Services
Translated Service: Original
Inbound Interface: Any
Outbound Interface: X1
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 38

Expert Comment

by:Aaron Tomosky
Comment Utility
What ip is "mail server public"?
0
 
LVL 4

Author Comment

by:Cobra25
Comment Utility
Mail Server Public is Outside Ip: x.x.x.55
0
 
LVL 38

Accepted Solution

by:
Aaron Tomosky earned 500 total points
Comment Utility
Change original service to any and see if that fixes it.
0
 
LVL 4

Author Comment

by:Cobra25
Comment Utility
I changed Outbound Interface to Any and that got it. Thanks Aaron!
0
 
LVL 68

Expert Comment

by:Qlemo
Comment Utility
I've requested that this question be closed as follows:

Accepted answer: 0 points for Cobra25's comment #a40428926

for the following reason:

This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0
 
LVL 38

Expert Comment

by:Aaron Tomosky
Comment Utility
I can't see comment numbers from the mobile site but this comment of mine was the final solution:
Change original service to any and see if that fixes it.
0
 
LVL 68

Expert Comment

by:Qlemo
Comment Utility
The last Author Comment tells different. The Outbound interface needed to get changed. No mentioning of the service being an issue.

Qlemo
Cleanup Volunteer
0
 
LVL 4

Author Comment

by:Cobra25
Comment Utility
Please award Aaron points, he got me to the solution.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Network Upgrade 4 54
New modem? 4 59
ASA 5510 PAT question 1 20
What network switches should I use for Fiber WAN project 4 18
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now