Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Full Nat Rule

On my Sophos UTM 9.3 I had a Full NAT rule that allowed me to go from the following:

Lan address to the Wan Address( my ddns address) and then it would send me back to my whichever internal lan server I wanted.

I tried making this same rule in XG but it never seems to work.



This thread was automatically locked due to age.
Parents
  • Hi Daryl,

    You should be able to first create the NAT object under: Objects > Policies > Network Address Translation then specify the WAN port of the appliance.
    Once created you can go to Policies > Add Firewall Rule: Specify the LAN interface as the source and the destination going outside your network.

    Fill out any of the necessary information (specify serivices etc.) and make sure once you get to the "Routing" section you turn "Rewrite source address (Masquerading)" on. You can specify different services so the address gets routed to the correct internal server you need.

    Hopefully this points you in the right direction, please let us know if you need more clarification.
Reply
  • Hi Daryl,

    You should be able to first create the NAT object under: Objects > Policies > Network Address Translation then specify the WAN port of the appliance.
    Once created you can go to Policies > Add Firewall Rule: Specify the LAN interface as the source and the destination going outside your network.

    Fill out any of the necessary information (specify serivices etc.) and make sure once you get to the "Routing" section you turn "Rewrite source address (Masquerading)" on. You can specify different services so the address gets routed to the correct internal server you need.

    Hopefully this points you in the right direction, please let us know if you need more clarification.
Children
No Data