Solved

SonicWALL TZ400 Access Single X0 Interface IP from Many X3 Interface IP’s

Posted on 2016-11-09
4
19 Views
Last Modified: 2016-11-15
I want to be able to access X0 (LAN) IP 192.168.1.51 from X3 (LAN2) 172.16.1.0/24

1.      X0 (LAN) and X3 (LAN2) are trusted interfaces and have corresponding Any/Any access to each other as separate firewall rules (automatically created by SonicWALL when trusted is enabled).
2.      I created address object AO_X0_IP for 192.168.1.51 and a corresponding address object AO_X3_IP to translate to 172.16.1.51
3.      I then created address object AO_X3_RNG for 172.16.1.0/24 for full range of subnet
4.      I then created and enabled the following NAT policy
        a.      Original Source: AO_X3_RNG
        b.      Translated Source: Original
        c.      Original Destination: AO_X3_IP
        d.      Translated Destination: AO_X0_IP
        e.      Original Service: Any
        f.      Translated Service: Original
        g.      Inbound Interface: Any
        h.      Outbound Interface: Any

This all seems correct, but yet I cannot access, or even ping, X0 (LAN) IP 192.168.1.51 from X3 (LAN2) 172.16.1.0/24.   That is, when I'm on the X3 subnet and I ping 172.16.1.51 it should translate to 192.168.1.51 on X0 and reply back, but no joy.  Can anyone help me solve this problem?  Thank you.
0
Comment
Question by:Nathan Vanderwyst
  • 3
4 Comments
 
LVL 20

Expert Comment

by:masnrock
ID: 41882420
The translation actually sounds like an unnecessary layer of headaches. I would delete it, go to the access rules, and create a LAN > LAN rule that allows traffic from X3 to X0.

Is there a reason why you were trying to do NAT for this particular issue?
0
 

Author Comment

by:Nathan Vanderwyst
ID: 41883142
I want to separate the two LAN's so that there is no traffic between them except for hitting that single IP address.   Your suggestion did not work.
0
 

Accepted Solution

by:
Nathan Vanderwyst earned 0 total points
ID: 41883216
I was mistaken, my first NAT did work, it was just PING wouldn't work.  I did change the Original Source to X3 Subnet instead of the custom address object of the full ip range since it was redundant.  Thank you for your help.

Original Source: X3 Subnet
Translated Source: Original
Original Destination: AO_X3_IP
Translated Destination: AO_X0_IP
Original Service: Any
Translated Service: Original
Inbound Interface: Any
Outbound Interface: Any
0
 

Author Closing Comment

by:Nathan Vanderwyst
ID: 41887625
I did not know that PING did not work across the interfaces.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

We sought a budget ($5,000) firewall solution that would provide all the performance we needed with no single point of failure.  Hosting a SAAS web application in our datacenter, it was critical that we find a way to keep connectivity up and inbound…
Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now