This section provides an example for configuring 3-Tuple NAT for intranet users to access the Internet.
Networking Requirements
An enterprise has deployed a FW as a security gateway on the intranet border. A source NAT policy needs to be configured on the FW so that users on the intranet 10.1.1.0/24 can access the Internet. In addition to the public IP address of the WAN interface on the FW, the enterprise has also been allocated public addresses 1.1.1.10 through 1.1.1.15 by the Internet service provider (ISP). The FW uses source NAT to map private addresses of the intranet (10.1.1.0/24) to these public addresses. Figure 1 illustrates the source NAT policy networking. The router is an access gateway on the ISP network.
P2P services, such as file sharing, voice communication, and video service between the users on the intranet and the hosts on the Internet can traverse NAT, regardless of which side initiates the service.
Figure 1 Source NAT policy networking
Data Planning
Item
|
Data
|
Description
|
GigabitEthernet 0/0/1
|
IP address: 10.1.1.1/24
Security zone: trust
|
Set the default gateway address on each intranet host to 10.1.1.1.
|
GigabitEthernet 0/0/2
|
IP address: 1.1.1.1/24
Security zone: untrust
|
1.1.1.1/24 is a public address provided by the ISP.
|
Intranet segment that is allowed to access the Internet
|
10.1.1.0/24
|
-
|
Public addresses mapped to private addresses
|
1.1.1.10 to 1.1.1.15
|
Public IP address in full-cone NAT
|
Routing information
|
FW's default route
|
Destination address: 0.0.0.0
Next hop address: 1.1.1.254
|
Configure a default route on the FW to direct intranet traffic to the ISP network.
|
Router's static route
|
Destination address: 1.1.1.10 to 1.1.1.15
Next hop address: 1.1.1.1
|
The public addresses mapped to private addresses are not assigned to physical ports. As a result, the router cannot use a routing protocol to discover routes to the public addresses. Ask the ISP network administrator to configure a static route destined for the network segment address of the address pool on the router.
|
Configuration Roadmap
The configuration roadmap is as follows:
- Assign IP addresses to interfaces, add the interfaces to security zones, and configure network connectivity.
- Configure a security policy to allow a specific intranet segment to access the Internet.
- Configure a NAT address pool.
- Configure a source NAT policy for translating source addresses between private and public address realms when hosts on the specific intranet segment access the Internet.
- Configure a default route on the FW to direct intranet traffic to the ISP router.
- Configure the IP address of the FW interface connected to the intranet as the default gateway address on each intranet host so that intranet traffic is directed to the FW when intranet hosts access the Internet.
- Configure a static route on the ISP router for forwarding Internet traffic to the FW.
Procedure
- Set IP addresses for interfaces on the FW and assign the interfaces to security zones.
- Set the IP address of GigabitEthernet 0/0/1 and assign the interface to a security zone.
Choose .
In Interface List, click
of GigabitEthernet 0/0/1 and set the parameters as follows:
Zone
|
trust
|
IPv4
|
IP Address
|
10.1.1.1/24
|
Click OK.
- Set the IP address of GigabitEthernet 0/0/2 and assign the interface to a security zone.
In Interface List, click
of GigabitEthernet 0/0/2 and set the parameters as follows:
Zone
|
untrust
|
IPv4
|
IP Address
|
1.1.1.1/24
|
Click OK.
- Configure a security policy to allow users on a specific network to access the Internet.
Choose .
In Security Policy List, click Add, select Add Security Policy, and configure a security policy based on the following parameter values.
Name
|
policy1
|
Source Zone
|
trust
|
Destination Zone
|
untrust
|
Source Address/Region
|
10.1.1.0/24
|
Action
|
Permit
|
Click OK.
- Configure a NAT address pool and a NAT policy.
Choose .

In Source Translation Address Pool List, click Add and configure a NAT address pool based on the following parameter values.

Click OK.
Choose .

In NAT Policy List, click Add and configure a NAT policy based on the following parameter values.

Click OK.
- Configure a default route on the FW, so that traffic from the private network can be forwarded to the ISP router.
Choose .
In Static Route List, click Add and configure a default route based on the following parameter values.
Protocol
|
IPv4
|
Destination Address/Mask
|
0.0.0.0/0.0.0.0
|
Next Hop
|
1.1.1.254
|
Click OK.
- Optional: Enable endpoint-independent filtering function. By default, the function is enabled. If the function is disabled, configure a security policy for traffic from the public network to the private network.
[FW] firewall endpoint-independent filter enable
- On each PC, configure the IP address of the FW interface connected to the intranet as the default gateway address to direct intranet traffic to the FW. The detailed configuration process is omitted.
- On the router, configure a static route destined for the network segment of the address pool (1.1.1.10 to 1.1.1.15) and set the next-hop address of the static route to 1.1.1.1 so that Internet traffic destined for the intranet server can be forwarded by the FW.
Contact your ISP administrator to perform this step.
Configuration Scripts
Configuration script for the FW:
#
sysname FW
#
interface GigabitEthernet0/0/1
undo shutdown
ip address 10.1.1.1 255.255.255.0
#
interface GigabitEthernet0/0/2
undo shutdown
ip address 1.1.1.1 255.255.255.0
#
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/1
#
firewall zone untrust
set priority 5
add interface GigabitEthernet0/0/2
#
ip route-static 0.0.0.0 0.0.0.0 1.1.1.254
#
nat address-group addressgroup1 0
mode full-cone global
route enable
section 0 1.1.1.10 1.1.1.15
#
security-policy
rule name policy1
source-zone trust
destination-zone untrust
source-address 10.1.1.0 24
action permit
#
nat-policy
rule name policy_nat1
source-zone trust
destination-zone untrust
source-address 10.1.1.0 24
action source-nat address-group addressgroup1
#
return