Sophos XG D-NAT Configuration for Secondary ISP
From Notes_Wiki
Revision as of 15:26, 19 May 2025 by Darshan (talk | contribs) (Created page with "Home > Enterprise security devices or applications > Sophos Firewall or IPS > Sophos XG D-NAT Configuration for Secondary ISP == Configure D-NAT Policies for the Secondary ISP == === Open Firewall Rules Section === # Navigate to the top menu and go to: '''Rules and Policies''' > '''Firewall Rules'''. === Add New D-NAT Rule === # Click on the '''Add Firewall Rule''' button. # From the list of options, select '''Server Assistant (D-NAT)'''....")
Home > Enterprise security devices or applications > Sophos Firewall or IPS > Sophos XG D-NAT Configuration for Secondary ISP
Configure D-NAT Policies for the Secondary ISP
Open Firewall Rules Section
- Navigate to the top menu and go to: Rules and Policies > Firewall Rules.
Add New D-NAT Rule
- Click on the Add Firewall Rule button.
- From the list of options, select Server Assistant (D-NAT).
Enter Internal Server IP
- In the Server Details window, enter the Private IP address of the internal server that needs to be accessed from outside.
- Click on Next.
Choose Public IP (from ISP)
- In the Public IP Assignment section, select the appropriate Public IP address from the ISP through which the server should be accessible.
- Click on Next.
(Optional) Select Required Services
- If needed, select specific Services (e.g., HTTP, HTTPS, RDP).
- Click on Next.
Define External Source Access
- In the Source Access screen, select ANY under External Source Networks and Devices to allow traffic from any public source.
- Click on Next.
Review and Save Configuration
- On the Review Summary page, cross-verify all the entered details.
- Click on Save and Finish.
Verify Rule Creation
- After saving, go to:
- Rules and Policies > Firewall Rules to confirm the new rule.
- Rules and Policies > NAT Rules to verify that the corresponding D-NAT rule has been created.
Validation
- The configured server should now be accessible:
- Internally (from the local network)
- Externally (from the internet via the selected ISP public IP)
Home > Enterprise security devices or applications > Sophos Firewall or IPS > Sophos XG D-NAT Configuration for Secondary ISP