This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Masquerading & Web protection

there is such a question, my topology: router - UTM - end user.

I use transparent mode.

 

if enabled web protection, i need to enable masquerading (internal > external (internet)?

when enabled web protection, enable or disable NAT masquerading, does not affect the operation of the Internet...



This thread was automatically locked due to age.
Parents Reply
  • It's been like this since I can remember, Emile, for all proxies.  For example, if you want outbound SMTP to come from an IP other than the primary one on the External interface and your mail server is relaying off the UTM's SMTP Proxy, the SNAT must have a Source of "External (Address)" instead of the internal IP of the mail server.

    The help for Multipath rules includes:

    Note – Basically, persistence by source cannot work when using a proxy because the original source information is lost. The HTTP proxy however is an exception: Traffic generated by the HTTP proxy will match against the original client source IP address and thus complies with interface persistence rules By source, too.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data