<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>WAF &amp;amp; SNAT</title><link>https://community.sophos.com/utm-firewall/f/web-server-security/115908/waf-snat</link><description>Been a while so apologies.... 
 If you have a webserver behind WAF, does the webserver reply on the address the WAF is using? 
 eg. webserver sits on a subnet that is maquarading to PUBLIC IP X, WAF is using PUBLIC IP Y for https 
 In the above example</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: WAF &amp; SNAT</title><link>https://community.sophos.com/thread/417753?ContentTypeID=1</link><pubDate>Wed, 16 Oct 2019 16:23:07 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:54289107-c4f1-4494-870d-ccc992623c20</guid><dc:creator>Jaydeep</dc:creator><description>&lt;p&gt;Yes, since the incoming request would be on the port and URL specified withing WAF configuration on UTM and also on Webserver, any incoming web request will be replied from the same IP. For example, if your website is hosted on X address and you&amp;#39;ve configured it on UTM and on WAF to forward it to your Webserver, it will be replying using that same X address.&lt;/p&gt;
&lt;p&gt;For all other traffic going out of your Webserver to the Internet, since the destination port will be different and services as well, it will go ahead using MASQ or SNAT rule (if any) specified in your UTM.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>