simple port forwarding

Hello

V18 rules is confusing for now, how do i create a simple port forwarding, to allow access to a port from outside?

Thanks

Parents
  • It is very confusing:

    1. Create a NAT, under Rules and policies. For example,
    2. Create a Firewall rule to allow traffic from Any to WAN zone where destination network/host is the WAN ip address

  • Hello Luk,

    please check ( below ) the DNAT firewall rule and appropriate DNAT rule. Especially focus on the Destination Zone and the Destination Network in the firewall rule. The Destination Zone is LAN zone and #PortB: 1 is the alias address on the WAN interface! It is very interesting interconnection of the Destination Zone and the Destination Network!

    This is not me, but it is the result of business rule migration from v17.5 to v18 EAP1. But it really works. I learned something new again thanks to Sophos ...

    However, it is important that the DNAT rule must be before the masquerading rule (MASQ) otherwise of course "matches" the User Portal. 

    Regards

    alda

    [:(]

     

     

     

     

  • this does not make sense. I guess it is a bug. The possible way that the DNAT should work are:

    • Source zone: wan
    • Source network: any or specific souce public ip
    • destination zone: internal
    • destination network: internal server where the service we want to publish is located

     

    Another way could be:

     

    • Source zone: any
    • Source network: any or specific souce public ip
    • destination zone: wan
    • destination network: WAN port or alias

     

    Anyway I liked the v17 wizard and WAF but it seems I am alone....

     

     

Reply
  • this does not make sense. I guess it is a bug. The possible way that the DNAT should work are:

    • Source zone: wan
    • Source network: any or specific souce public ip
    • destination zone: internal
    • destination network: internal server where the service we want to publish is located

     

    Another way could be:

     

    • Source zone: any
    • Source network: any or specific souce public ip
    • destination zone: wan
    • destination network: WAN port or alias

     

    Anyway I liked the v17 wizard and WAF but it seems I am alone....

     

     

Children