Help us enhance your Sophos Community experience. Share your thoughts in our Sophos Community survey.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Webserver protection vs Firewall nat rules

I was only successful using the webserver protection option to setup an internal webserver with its own external static ip address. For some reason using various NAT rules/firewall rules I couldn't succeed. Very basic setup, is that the only way to setup webservers?

my example:  firewall external  ip address  xx.***.***.5
webserver via external:  xx.***.***.6
used dnat rules to take traffic from any, using http, to external (.6) change dest to internal webserver, service to http

also, noticed that using webserver protection doesn't create any firewall rules?


This thread was automatically locked due to age.
Parents
  • Check #3 through #5 in Rulz.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • must be missing something since I went through rules 3-5 and everything looks fine. I do see it passing though fine in the firewall log?  .251 being my external ip address for the webserver.

    09:17:08  NAT rule #2  TCP    
    70.192.2.180  :  9499
    → 
    66.210.118.251  :  80
      
    [SYN]  len=64  ttl=44  tos=0x00  srcmac=0:24:c4:5e:2e:89  dstmac=0:1a:8c:50:18:25
Reply
  • must be missing something since I went through rules 3-5 and everything looks fine. I do see it passing though fine in the firewall log?  .251 being my external ip address for the webserver.

    09:17:08  NAT rule #2  TCP    
    70.192.2.180  :  9499
    → 
    66.210.118.251  :  80
      
    [SYN]  len=64  ttl=44  tos=0x00  srcmac=0:24:c4:5e:2e:89  dstmac=0:1a:8c:50:18:25
Children
No Data