This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM interface to connect to on-the-premises router (behind the firewall) with a WAN IP

On this diagram we have several objects to look at

WAN IP = 12.12.12.35

LAN IP of UTM = 8.8.8.8

WAN IP of Router behind firewall = 12.12.12.36

LAN IP of Router behind firewall 8.8.8.4

 

 

How would you configure Port 4 to plug a cable from the UTM to the WAN Port of the Router? 

 

I plan to configure interface X4 = 12.12.12.36/32 proxy-arp enabled

 

now granted if the firewall rules are correct to allow full ip from 12.12.12.36 to get out through the internet to connect to defined router (10.10.10.10)

I think the Utm will see traffic from defined router (10.10.10.10) from any source (port 2 wan 12.12.12.35), permit it to pass to port 4 12.12.12.36.  Transparent traffic ???

In theory this should work right?  

If the router because of vpn tunnel policies didn't need the wan ip configured a nat rule would be sufficient.  

Other alternative create dmz ip for the interface and have the router's wan ip changed to avoid messing up the routing table.



This thread was automatically locked due to age.
Parents
  • I would change the WAN Interface definition to "Ethernet Bridge" and add NIC X4 to it.  Try first without Proxy ARP, but I bet you will need it.

    The alternative is to create a DMZ with a public subnet and to ask your ISP to route traffic to it via 12.12.12.35.  This requires no bridge and no Proxy ARP, but uses a separate Interface definition with an IP in the public subnet of the public DMZ.

    Both approaches require a firewall rule.

    Cheers - Bob
    PS Using the IPs of the Google name servers created cognitive dissonance when I first tried to understand what you wanted to accomplish.  I guessed that you meant IPs in 10.10.10.0/24, but I admit I'm still not clear.

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply Children
No Data