

Specify the translation settings for source, destination, services, and interfaces to match traffic flowing through interfaces and VPN tunnels. Original source, destination, and service are the pre-NAT entities of traffic when it enters Sophos Firewall. Translated source, destination, and services are the post-NAT entities of traffic when it exits Sophos Firewall. You can select the original source, destination, and services or create new ones. Specify the pre-NAT source objects of outgoing traffic. To create an inbound NAT rule when the inbound IP address is unknown, select Any. IP addresses of the original source objects are translated to the IP addresses that you specify. Use this to perform source NAT (SNAT) for outgoing traffic. By default, masquerading translates the original IP address to the outbound interface IP address. However, for route-based VPNs configured with Any for the local and remote subnets or IP version set to Dual, the firewall translates the original source to the XFRM IP address for the translated source set to MASQ. To create an inbound NAT rule, select Original. Specify the pre-NAT destination objects of incoming traffic. To create an outbound NAT rule, select Any. IP addresses of the destination objects are translated to the IP addresses or FQDN that you specify. To create an outbound NAT rule, select Original. Services are a combination of protocols and ports.

To create an outbound NAT rule, this is generally set to Any. Original services are translated to the services that you specify. Use this for port address translation (PAT). If you've specified more than one original service or set it to Any, set the translated service to Original. The translated protocol must match the original protocol. You can translate original service ports to a single or equal number of translated service ports. You can use this to port forward traffic to internal servers, for example, specify TCP port 443 to forward incoming HTTPS traffic to an internal web server. Select the interfaces through which traffic specified in this rule enters Sophos Firewall.įor destination NAT, you can specify Any.įor VPNs, set this interface to Any, since VPNs are not interfaces. Select the interfaces from which traffic specified in this rule exits Sophos Firewall.įor VPNs and for destination NAT rules that translate public IP addresses to private IP addresses, set this interface to Any. Select Override source translation for specific outbound interfaces to apply interface-specific source translation. This option applies only to source NAT rules.Select an option in Outbound interface and Translated source (SNAT).Select Create loopback rule to allow internal hosts to access other internal hosts, for example, servers.Select Create reflexive rule to create a mirror rule that reverses the matching criteria of the rule from which it’s created. You can create loopback and reflexive rules for destination NAT rules. They are created, using the original NAT rule ID and name. Select a Load balancing method from the following options to send requests to the internal hosts (translated destination): Changing the original NAT rule settings later doesn’t change loopback and reflexive rule settings.Round robin: Sends requests to each server sequentially.First alive: Sends requests to the first available server.
