Solved

SonicWALL NAT configuration

Posted on 2016-07-25
9
79 Views
Last Modified: 2016-08-01
Hi Guys,

I have two web servers behind a SonicWall TZ400 and two seperate public IP's coming in.
I would like to publish the one server on public IP-1 and the other on public IP-2.

I've tried a couple of scenarios, but the packet destination address show as the WAN address of the SonicWALL router
(doesn't show the original public IP address)

There is another router infront of the SonicWALL and this router is natting through from the internet to the SonicWall.

Am I correct in thinking the "front-end' router is removing the "original destination" from the incoming packets?

Is there any way redirecting incoming traffic in the SonicWALL based on "original destination" (Public IP)?
0
Comment
Question by:Rupert Eghardt
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 22

Assisted Solution

by:David Atkin
David Atkin earned 500 total points
ID: 41727571
Hi there,

Have you configured the additional WAN addresses on your Sonicwall?

If so, you should be able to do this via the 'Public Server' Wizard in the top right of the sonicwall.

It will ask you to specify the external public IP address and then the local internal server address.

It would be strange for your ISP to be altering any of the destination packets.
0
 

Author Comment

by:Rupert Eghardt
ID: 41727578
Thanks David,

I published 2 x servers via the 'Public Server' Wizard.
Each on it's own public IP.  The wizard created two network objects for the public IP's.

I couldn't access the servers externally with the NAT's created by the wizard.
I checked the packet monitor and it shows Dst=[192.168.1.4]
This is the local WAN address of the SonicWALL.

After changing my NAT rule from public-IP to "WAN Interface IP", the server was accessible from the internet.
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 41728869
Hi Rupert,

Just to confirm, is this now resolved?
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:Rupert Eghardt
ID: 41728890
Not yet, I suspect the ISP is translating the traffic, thus packet losing the public IP ...
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 41728908
If thats the case then you will need to contact them to get it confirmed. It would be a strange thing for them to do though!
0
 

Author Comment

by:Rupert Eghardt
ID: 41728940
Could there be any other reason why the packet monitor would display original destination as
Dst=[192.168.1.4] ?

I've inspected the packet data and don't see the public IP anywhere?
0
 

Accepted Solution

by:
Rupert Eghardt earned 0 total points
ID: 41732033
I believe the ISP is translating the public IP to private IP, public IP not accessible after the ISP DSL router.
Only solution is to setup two seperate networks in ISP DSL router, translating to two seperate private IP's.  Current DSL router not equipped for two interfaces, applied for router upgrade.
0
 
LVL 22

Expert Comment

by:David Atkin
ID: 41732860
Thank you for letting us know the solution.  Glad you managed to resolve your problem.
0
 

Author Closing Comment

by:Rupert Eghardt
ID: 41737183
Problem not solved, applied for DSL router upgrade, will be using two private IP's from DSL router.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Show IP BGP Information 10 73
How to migrate from Juniper srx to pan 7.x? 2 36
Failover for DMVPN 3 59
Connectivity drops 9 80
This subject  of securing wireless devices conjures up visions of your PC or mobile phone connecting to the Internet through some hotspot at Starbucks. But it is so much more than that. Let’s look at the facts: devices#sthash.eoFY7dic.
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question