Solved

Sonicwall Change Outbound NAT for Server

Posted on 2014-11-01
16
157 Views
Last Modified: 2014-12-25
Hey guys,

I have a Sonicwall NSA2400. Now one server, i opened a few ports to it and its working fine from the Outside. But when this server goes to the Internet, its going out with the Firewall's outside IP, i need to change this to a different IP. How would i do that on this firewall?
0
Comment
Question by:Cobra25
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 6
  • 2
  • +1
16 Comments
 

Expert Comment

by:bNetworked
ID: 40418032
What IP do you need to change it to and why?  Normal operation for a firewall is to use NAT (network address translation) to make everything look like it's coming from the internet side IP to protect all the computers behind it from being open and vulnerable to attack.  Depending on what you want to do, it may be possible to do with the Sonicwall using virtual interfaces or DMZ.  I think that we need more information in order to address this.
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 40418194
Yes you can do this. First make an address object for the ip you want it to be, Then make a nat rule for that server where translated from is that address object
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 40418199
Alternatively I suggest you use the public server wizard instead of doing this manually. Then edit the service group to have the services you want.
0
Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

 
LVL 4

Author Comment

by:Cobra25
ID: 40422120
So its for my mail server.
Internal ip -- 192.168.60.10
Outside Ip: x.x.x.55
Firewall outside ip: x.x.x.60

So from the outside to in using the 55 address it works fine. When the mail server goes out to the internet/sends email, it goes out as the .60 which is causing mail to get blocked because the rdns/forward dns do not match.
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40428816
Any thoughts guys?
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 40428837
Is .60 the default for all traffic?

I've already said how to do this, Just make a nat rule from the exchange host to the Internet (X1 probably) translated source .55.
http://help.mysonicwall.com/sw/eng/305/ui2/23100/Network/Add_NAT_Policy.htm
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40428880
Aaron - thanks for the response.

Yes , .60 is the default.

Do i make a new rule or can i modify the existing NAT rule?

Right now my NAT Policy for this server is:
Original Source: Mail Server Private
Translated Source: Mail Server Public
Original Destination: Any
Translated Destination: Original
Original Service: Mail Server Services
Translated Service: Original
Inbound Interface: Any
Outbound Interface: X1
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 40428892
What ip is "mail server public"?
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40428907
Mail Server Public is Outside Ip: x.x.x.55
0
 
LVL 39

Accepted Solution

by:
Aaron Tomosky earned 500 total points
ID: 40428920
Change original service to any and see if that fixes it.
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40428926
I changed Outbound Interface to Any and that got it. Thanks Aaron!
0
 
LVL 70

Expert Comment

by:Qlemo
ID: 40511868
I've requested that this question be closed as follows:

Accepted answer: 0 points for Cobra25's comment #a40428926

for the following reason:

This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 40511869
I can't see comment numbers from the mobile site but this comment of mine was the final solution:
Change original service to any and see if that fixes it.
0
 
LVL 70

Expert Comment

by:Qlemo
ID: 40511935
The last Author Comment tells different. The Outbound interface needed to get changed. No mentioning of the service being an issue.

Qlemo
Cleanup Volunteer
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40512405
Please award Aaron points, he got me to the solution.
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco 3650 switch licensing 6 79
How can I test a Deny All In Firewall rule? 2 58
Simple Fibre Question 6 59
What's API gateway/firewall & how it's used 10 81
Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
When posting a question about a Cisco ASA, Cisco Router or Cisco Switch, it can aid diagnosis if a suitably sanitised copy of the config is provided. It is much better to leave as much of the configuration as original as possible, as it could be tha…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Finding and deleting duplicate (picture) files can be a time consuming task. My wife and I, our three kids and their families all share one dilemma: Managing our pictures. Between desktops, laptops, phones, tablets, and cameras; over the last decade…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question