gw-world:/> add Address IPAddress wwwsrv_priv Address=10.10.10.5
Publish the five public IPv4 addresses on the wan interface using ARP publish. A CLI command
like the following is needed for each IP address:
gw-world:/> add ARP Interface=wan IP=195.55.66.77 mode=Publish
Create a SAT IP rule for the translation:
gw-world:/> add IPRule Action=SAT
Finally, create an associated Allow rule:
gw-world:/> add IPRule Action=Allow
Web Interface
Create a SAT IP rule for the translation:
1.
Go to: Policies > Firewalling > Main IP Rules > Add > IP Rule
2.
Specify a suitable name for the rule, for example SAT_HTTP_To_DMZ
3.
Now enter:
•
Action: SAT
•
Service: http-all
•
Source Interface: any
•
Source Network: all-nets
•
Destination Interface: wan
•
Destination Network: wwwsrv_pub
•
SAT Translate: Destination IP
•
New IP Address: wwwsrv_priv
•
Enable the option: All-to-One
4.
Click OK
Finally, create an associated Allow rule:
Service=http-all
SourceInterface=any
SourceNetwork=all-nets
DestinationInterface=wan
DestinationNetwork=wwwsrv_pub
SATTranslateToIP=wwwsrv_priv
SATTranslate=DestinationIP
SATAllToOne=Yes
Service=http-all
SourceInterface=any
SourceNetwork=all-nets
DestinationInterface=wan
DestinationNetwork=wwwsrv_pub
598
Chapter 7: Address Translation