< Home

Web: Example for Configuring Bidirectional NAT for Internet Users to Access Intranet Servers (Source NAT+Static Destination NAT)

This section provides an example for configuring bidirectional NAT for Internet users to access intranet servers.

Networking Requirements

The FW serves as a security gateway at the border of an enterprise network. Destination NAT needs to be configured on the FW so that intranet web and FTP servers can provide services externally. In addition to the IP addresses of Internet interfaces, the enterprise applies for public IP addresses (1.1.10.10 and 1.1.10.11) for the intranet server to provide services. In addition, a source NAT policy is required to simplify the return route configuration for the intranet servers, so that the intranet servers send response packets to the FW by default. Figure 1 illustrates the static mapping networking. The router is an access gateway on the ISP network.

Figure 1 Networking diagram for configuring bidirectional NAT for Internet users to access Intranet servers (source NAT+destination NAT)

Data Planning

Item Data Description

GigabitEthernet 0/0/1

IP address: 1.1.1.1/24

Security zone: untrust

1.1.1.1/24 is a public address provided by the ISP.

GigabitEthernet 0/0/2

IP address: 10.2.0.1/24

Security zone: dmz

Intranet servers use 10.2.0.1 as the default gateway address.

Addresses in the source NAT address pool

10.2.0.10 to 10.2.0.15

-

Addresses in the destination NAT address pool

10.2.0.7 to 10.2.0.8

-

Routing information

Default route

Destination address: 0.0.0.0

Next hop address: 1.1.1.254

Configure a default route defined for the ISP router on the FW to direct intranet traffic to the router.

Configuration Roadmap

  1. Assign IP addresses to interfaces, add the interfaces to security zones, and configure network connectivity.
  2. Configure a security policy for traffic between Internet users and intranet servers.
  3. Configure a destination NAT policy to translate the destination addresses of packets sent from the Internet to an intranet server to addresses in the destination NAT address pool.
  4. Configure a source NAT policy to translate the source addresses of packets sent from the Internet to an intranet server to addresses in the source NAT address pool.
  5. Configure a default route on the FW to direct intranet traffic to the ISP router.
  6. Configure static routes destined for public addresses of intranet servers on the router.

Procedure

  1. Set IP addresses for interfaces on the FW and assign the interfaces to security zones.
    1. Set the IP address of GigabitEthernet 0/0/1 and assign the interface to a security zone.

      1. Choose Network > Interface.

      2. In Interface List, click of GigabitEthernet 0/0/1 and set the parameters as follows:

        Zone

        untrust

        IPv4

        IP Address

        1.1.1.1/24

      3. Click OK.

    2. Set the IP address of GigabitEthernet 0/0/2 and assign the interface to a security zone.

      1. In Interface List, click of GigabitEthernet 0/0/2 and set the parameters as follows:

        Zone

        dmz

        IPv4

        IP Address

        10.2.0.1/24

      2. Click OK.

  2. Configure a security policy for traffic between Internet users and intranet servers.

    1. Choose Policy > Security Policy > Security Policy.

    2. In Security Policy List, click Add, select Add Security Policy, and configure a security policy based on the following parameter values.

      Name

      policy1

      Source Zone

      untrust

      Destination Zone

      dmz

      Destination Address/Region

      10.2.0.0/24

      Action

      Permit

    3. Click OK.

  3. Configure NAT address pools and NAT policies.

    1. Choose Policy > NAT Policy > NAT Policy > Source Translation Address Pool.

    2. In Source Translation Address Pool List, click Add and configure a NAT address pool based on the following parameters.

    3. Click OK.

    4. Choose Policy > NAT Policy > NAT Policy > Destination Translation Address Pool.

    5. In Destination Translation Address Pool List, click Add and configure a NAT address pool based on the following parameters.

    6. Click OK.

    7. Choose Policy > NAT Policy > NAT Policy.

    8. In NAT Policy List, click Add and configure a NAT policy based on the following parameters.

    9. Click OK.

  4. Configure a black-hole route on the FW, so that traffic from intranet servers can be forwarded to the ISP router.
    1. Choose Network > Route > Static Route.
    2. In Static Route List, click Add and configure a black-hole route based on the following parameter values.

      Protocol

      IPv4

      Destination Address/Mask

      1.1.10.10/255.255.255.0

      Next Hop

      NULL0

    3. Repeat the preceding steps to configure the black-hole route as follows.

      Protocol

      IPv4

      Destination Address/Mask

      1.1.10.11/255.255.255.0

      Next Hop

      NULL0

    4. Click OK.
  5. Enable NAT ALG for FTP.
    1. Choose Policy > ASPF Configuration.

    2. Select FTP.
  6. Configure a default route on the FW, so that traffic from intranet servers can be forwarded to the ISP router.
    1. Choose Network > Route > Static Route.
    2. In Static Route List, click Add and configure a default route based on the following parameter values.

      Protocol

      IPv4

      Destination Address/Mask

      0.0.0.0/0.0.0.0

      Next Hop

      1.1.1.254

    3. Click OK.
  7. Configure a static route to public address (1.1.10.10 and 1.1.10.11) with the next hop being 1.1.1.1 on the router so that traffic destined for the server can be sent to the FW.

    Contact your ISP administrator to perform this step.

Configuration Scripts

Configuration script for the FW:

#
 sysname FW
#
interface GigabitEthernet0/0/1
 undo shutdown
 ip address 1.1.1.1 255.255.255.0 
#
interface GigabitEthernet0/0/2
 undo shutdown
 ip address 10.2.0.1 255.255.255.0 
#
firewall zone untrust
 set priority 5
 add interface GigabitEthernet0/0/1
#
firewall zone dmz
 set priority 50
 add interface GigabitEthernet0/0/2
# 
firewall interzone dmz untrust 
 detect ftp 
#
 ip route-static 0.0.0.0 0.0.0.0 1.1.1.254 
 ip route-static 1.1.10.10 255.255.255.255 NULL0 
 ip route-static 1.1.10.11 255.255.255.255 NULL0 
# 
nat address-group addressgroup1 0
 mode pat
 route enable
 section 0 10.2.0.10 10.2.0.15 
# 
destination-nat address-group addressgroup2 0
 section 10.2.0.7 10.2.0.8 
#  
security-policy   
  rule name policy1  
    source-zone untrust 
    destination-zone dmz 
    destination-address 10.2.0.0 24 
    action permit 
#  
nat-policy  
  rule name policy_nat1 
    source-zone untrust 
    destination-address range 1.1.10.10 1.1.10.11  
    service http
    service ftp
    action source-nat address-group addressgroup1  
    action destination-nat static address-to-address address-group addressgroup2
# 
return
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >