<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>transparent/split and NAT</title><link>https://community.sophos.com/utm-firewall/f/remote-ethernet-device-red/122082/transparent-split-and-nat</link><description>Hi, 
 
 I have a good established RED setup for a few remote sites that are under our control and all use Unified/Standard mode, and we extend our LAN address space out to those, with DHCP relayed from the main site. This works well. 
 However, I have</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: transparent/split and NAT</title><link>https://community.sophos.com/thread/444056?ContentTypeID=1</link><pubDate>Fri, 31 Jul 2020 14:34:44 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b6325c54-dc9f-4598-b1f3-0bd8d932f558</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;Hi Jon and welcome to the UTM Community!&lt;/p&gt;
&lt;p&gt;If I understand what you&amp;#39;re trying to accomplish, a&amp;nbsp;Full NAT&amp;nbsp;should be what you want.&amp;nbsp; If that didn&amp;#39;t work, show us the Edit of your NAT rule.&lt;/p&gt;
&lt;p&gt;If you have a duplicate subnet at two locations,&amp;nbsp;instead of a RED,&amp;nbsp;you will need a UTM with a Network Protection subscription at the duplicate location.&lt;/p&gt;
&lt;p&gt;My usual recommendation is for internal subnets to be in the 172.16.0.0/12 range.&amp;nbsp; Reserve 192.168.0.0/16 for public hotspots and home users.&amp;nbsp; Reserve 10.0.0.0/8 for giant multinationals, ISPs, etc.&lt;/p&gt;
&lt;p&gt;Cheers - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>