NAT question when migrating config.

Reply
L3 Networker

NAT question when migrating config.

Converting config from Nortel Connectivty switch to PA200.

3 interfaces

untrust - public ip - 202.3.41.0/28

trust:private ip - 10.10.10.0/24.

dmz-203.4.42.96/28

 

There is one to one mapping of few untrust ip to trust ips( to access trust ips from outside) and also few one to one mapping from dmz to trust.

When translating this to PA200.

I can do untrust to trust fine adding nat and security rules.

 

But when doing dmz to trust not sure about security polices and nat rules.

Will it be untrust to dmz(eg-203.4.42.99) -destination address translation ,translated address 10.10.10.100 in nat rule and untrust to trust(203.4.42.99) in security rule.

 

L5 Sessionator

Re: NAT question when migrating config.

I think it will be like that yes. But it's a bit weird concept i haven't seen yet. Are there also some servers with public address in DMZ? Or are there only NAT-ed servers? If it's only NAT-ed servers in DMZ than you can easily skip configuring DMZ on seperate interface and just configure that segment on untrust interface.

Nothing to do with your original question: but NAT into LAN is a very poor design regarding security. So if you have a chance try to redisgn the network.

L3 Networker

Re: NAT question when migrating config.

thanks for the info. But if you dont NAT in LAN how do u access LAN from untrust if u need to. Do u move them to dmz and just

have untrust to dmz access?

L5 Sessionator

Re: NAT question when migrating config.

Servers accesible from internet should be in DMZ. They should have only necessary services/applications open towards LAN. So if a server is breached, attacker still has no access into LAN and other networks (or very limited).

In what cases would you need direct access from internet to LAN? 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!