{"id":113,"date":"2022-04-25T07:29:09","date_gmt":"2022-04-25T11:29:09","guid":{"rendered":"https:\/\/pressbooks.bccampus.ca\/paloalto\/?post_type=chapter&#038;p=113"},"modified":"2026-02-18T15:28:37","modified_gmt":"2026-02-18T20:28:37","slug":"dnat","status":"publish","type":"chapter","link":"https:\/\/pressbooks.bccampus.ca\/paloalto\/chapter\/dnat\/","title":{"raw":"1.4 DNAT","rendered":"1.4 DNAT"},"content":{"raw":"<div class=\"textbox textbox--learning-objectives\"><header class=\"textbox__header\">\r\n<p class=\"textbox__title\">Learning Objectives<\/p>\r\n\r\n<\/header>\r\n<div class=\"textbox__content\">\r\n<ul>\r\n \t<li>Configure Destination NAT (DNAT)<\/li>\r\n \t<li>Configure WordPress<\/li>\r\n<\/ul>\r\n<\/div>\r\n<\/div>\r\n<div class=\"textbox\">\r\n\r\n<strong>Prerequisites<\/strong>:\r\n<ul>\r\n \t<li>SNAT for the Internet<\/li>\r\n \t<li>Security policy for Inside to Outside<\/li>\r\n \t<li>Interface configuration<\/li>\r\n \t<li>Knowledge of previous labs<\/li>\r\n<\/ul>\r\n<\/div>\r\n<div class=\"textbox shaded\"><strong>Scenario<\/strong>: When I think of DNAT (Destination Network Address Translation) I always think of the days of setting up port forwarding for all my favorite games just so I could host server friends can play on. You can think of DNAT like this too if it helps! The goal of this lab is to reach WordPress from the Outside. So, users only enter the IP address of Ethernet 1\/2 in the Outside webterm and the firewall redirects the traffic to WordPress.<\/div>\r\n\r\n[caption id=\"attachment_174\" align=\"aligncenter\" width=\"841\"]<img class=\"wp-image-174 size-full\" style=\"text-align: initial;font-size: 1em\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-36-27-image.png\" alt=\"Main scenario\" width=\"841\" height=\"733\" \/> Figure 1.55: Main scenario[\/caption]\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 74px\" border=\"0\"><caption>Table 1.7: Addressing Table<\/caption>\r\n<tbody>\r\n<tr style=\"height: 15px\">\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Device<\/th>\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Configuration<\/th>\r\n<\/tr>\r\n<tr style=\"height: 14px\">\r\n<td style=\"width: 50%;height: 14px\">WP (WordPress)<\/td>\r\n<td style=\"width: 50%;height: 14px\">eth0: 10.0.0.2\/24 GW: 10.0.0.1<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">PaloAlto<\/td>\r\n<td style=\"width: 50%;height: 15px\">Ethernet1\/1: 10.0.0.1\/24\r\nEthernet1\/2: DHCP\r\nManagement: 192.168.0.1\/24<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Management (WebTerm)<\/td>\r\n<td style=\"width: 50%;height: 15px\">eth0: 192.168.0.2\/24<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Outside (WebTerm)<\/td>\r\n<td style=\"width: 50%;height: 15px\">eth0: DHCP<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\" border=\"0\"><caption>Table 1.8: Zone Configuration<\/caption>\r\n<tbody>\r\n<tr>\r\n<th style=\"width: 50%\" scope=\"col\">Zone<\/th>\r\n<th style=\"width: 50%\" scope=\"col\">Interface<\/th>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Inside<\/td>\r\n<td style=\"width: 50%\">Ethernet1\/1<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Outside<\/td>\r\n<td style=\"width: 50%\">Ethernet1\/2<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<h2>Create Reference Addresses<\/h2>\r\nUnder <strong>Objects &gt; Addresses<\/strong>, click <strong>Add<\/strong>.\r\n\r\n[caption id=\"attachment_380\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-380 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT1.jpg\" alt=\"Add an address\" width=\"1026\" height=\"830\" \/> Figure 1.56: Add an address[\/caption]\r\n\r\nIn this window, we will add the IP of the WordPress server to reference it easier.\r\n\r\n[caption id=\"attachment_176\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-176 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-27-04-image.png\" alt=\"WordPress IP address\" width=\"1026\" height=\"830\" \/> Figure 1.57: WordPress IP address[\/caption]\r\n\r\nWe also want to put our firewall's \"public\" IP (the interface facing the NAT cloud) here too. You can find the firewall's DHCP address under <strong>network &gt; interfaces<\/strong>. Then click the hyperlink under IP address:\r\n\r\n[caption id=\"attachment_364\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-364 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9.jpg\" alt=\"Dynamic-DHCP Client IP address\" width=\"1024\" height=\"769\" \/> Figure 1.58: Dynamic-DHCP Client IP address[\/caption]\r\n\r\nFrom there you will find the IP address of the firewall:\r\n\r\n[caption id=\"attachment_178\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-178 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-30-12-image.png\" alt=\"Verify Dynamic-DHCP Client IP address\" width=\"1026\" height=\"830\" \/> Figure 1.59: Verify Dynamic-DHCP Client IP address[\/caption]\r\n<h2>Create a DNAT Policy<\/h2>\r\nUnder <strong>Policies &gt; NAT<\/strong>, click the Add button on the bottom.\r\n\r\n[caption id=\"attachment_381\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-381 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT2.jpg\" alt=\"Add a DNAT Policy\" width=\"1026\" height=\"830\" \/> Figure 1.60: Add a DNAT Policy[\/caption]\r\n\r\nUnder the Original Packet tab, configure these settings:\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\" border=\"0\"><caption>Table 1.9: DNAT Configuration<\/caption>\r\n<tbody>\r\n<tr>\r\n<th style=\"width: 50%\" scope=\"col\">Parameters<\/th>\r\n<th style=\"width: 50%\" scope=\"col\">Value<\/th>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Source Zone<\/td>\r\n<td style=\"width: 50%\">Outside<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Destination Zone<\/td>\r\n<td style=\"width: 50%\">Outside<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Destination Interface<\/td>\r\n<td style=\"width: 50%\">any<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Service<\/td>\r\n<td style=\"width: 50%\">service-http<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Destination Address<\/td>\r\n<td style=\"width: 50%\">(Firewall Public Address Here)<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n[caption id=\"attachment_180\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-180 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-42-34-image.png\" alt=\"DNAT Policy Rule- Original Packet\" width=\"1026\" height=\"830\" \/> Figure 1.61: DNAT Policy Rule- Original Packet[\/caption]\r\n\r\nUnder the translated packet tab, Destination Address Translation. Configure these:\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 61px\" border=\"0\"><caption>Table 1.10: DNAT Translated Packet Configuration<\/caption>\r\n<tbody>\r\n<tr style=\"height: 15px\">\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Parameters<\/th>\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Value<\/th>\r\n<\/tr>\r\n<tr style=\"height: 16px\">\r\n<td style=\"width: 50%;height: 16px\">Translation Type<\/td>\r\n<td style=\"width: 50%;height: 16px\">Static IP<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Translated Address<\/td>\r\n<td style=\"width: 50%;height: 15px\">(IP of WordPress here)<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Translated Port<\/td>\r\n<td style=\"width: 50%;height: 15px\">80<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n[caption id=\"attachment_181\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-181 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-44-24-image.png\" alt=\"DNAT Policy Rule- Translated Packet\" width=\"1026\" height=\"830\" \/> Figure 1.62: DNAT Policy Rule- Translated Packet[\/caption]\r\n\r\nThen, press <strong>OK<\/strong>.\r\n<h1>Security Policy for DNAT<\/h1>\r\nUnder <strong>Policies &gt; Security<\/strong>. Click <strong>Add<\/strong> at the bottom.\r\n\r\n[caption id=\"attachment_382\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-382 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT3.jpg\" alt=\"Add a Security Policy\" width=\"1026\" height=\"830\" \/> Figure 1.63: Add a Security Policy[\/caption]\r\n\r\nUnder the source tab, add the outside zone under the source zone:\r\n\r\n[caption id=\"attachment_183\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-183 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-15-image.png\" alt=\"Configuring the Source Zone\" width=\"1026\" height=\"830\" \/> Figure 1.64: Configuring the Source Zone[\/caption]\r\n\r\nUnder the destination tab, add the inside zone as the destination zone:\r\n\r\n[caption id=\"attachment_184\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-184 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-46-image.png\" alt=\"Configuring the Destination Zone\" width=\"1026\" height=\"830\" \/> Figure 1.65: Configuring the Destination Zone[\/caption]\r\n\r\nAfter that press <strong>OK<\/strong>, then <strong>Commit<\/strong>.\r\n<h2>Test DNAT<\/h2>\r\nUsing the Outside webterm. Navigate to the public IP address of your firewall. If any webpage shows up, whether it's the WordPress site or the one below. You got DNAT working!\r\n\r\n[caption id=\"attachment_185\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-185 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-49-08-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" \/> Figure 1.66: Verify your configuration[\/caption]","rendered":"<div class=\"textbox textbox--learning-objectives\">\n<header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n<li>Configure Destination NAT (DNAT)<\/li>\n<li>Configure WordPress<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox\">\n<p><strong>Prerequisites<\/strong>:<\/p>\n<ul>\n<li>SNAT for the Internet<\/li>\n<li>Security policy for Inside to Outside<\/li>\n<li>Interface configuration<\/li>\n<li>Knowledge of previous labs<\/li>\n<\/ul>\n<\/div>\n<div class=\"textbox shaded\"><strong>Scenario<\/strong>: When I think of DNAT (Destination Network Address Translation) I always think of the days of setting up port forwarding for all my favorite games just so I could host server friends can play on. You can think of DNAT like this too if it helps! The goal of this lab is to reach WordPress from the Outside. So, users only enter the IP address of Ethernet 1\/2 in the Outside webterm and the firewall redirects the traffic to WordPress.<\/div>\n<figure id=\"attachment_174\" aria-describedby=\"caption-attachment-174\" style=\"width: 841px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-174 size-full\" style=\"text-align: initial;font-size: 1em\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-36-27-image.png\" alt=\"Main scenario\" width=\"841\" height=\"733\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-36-27-image.png 841w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-36-27-image-300x261.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-36-27-image-768x669.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-36-27-image-65x57.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-36-27-image-225x196.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-36-27-image-350x305.png 350w\" sizes=\"auto, (max-width: 841px) 100vw, 841px\" \/><figcaption id=\"caption-attachment-174\" class=\"wp-caption-text\">Figure 1.55: Main scenario<\/figcaption><\/figure>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 74px\">\n<caption>Table 1.7: Addressing Table<\/caption>\n<tbody>\n<tr style=\"height: 15px\">\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Device<\/th>\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Configuration<\/th>\n<\/tr>\n<tr style=\"height: 14px\">\n<td style=\"width: 50%;height: 14px\">WP (WordPress)<\/td>\n<td style=\"width: 50%;height: 14px\">eth0: 10.0.0.2\/24 GW: 10.0.0.1<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">PaloAlto<\/td>\n<td style=\"width: 50%;height: 15px\">Ethernet1\/1: 10.0.0.1\/24<br \/>\nEthernet1\/2: DHCP<br \/>\nManagement: 192.168.0.1\/24<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Management (WebTerm)<\/td>\n<td style=\"width: 50%;height: 15px\">eth0: 192.168.0.2\/24<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Outside (WebTerm)<\/td>\n<td style=\"width: 50%;height: 15px\">eth0: DHCP<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\">\n<caption>Table 1.8: Zone Configuration<\/caption>\n<tbody>\n<tr>\n<th style=\"width: 50%\" scope=\"col\">Zone<\/th>\n<th style=\"width: 50%\" scope=\"col\">Interface<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Inside<\/td>\n<td style=\"width: 50%\">Ethernet1\/1<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Outside<\/td>\n<td style=\"width: 50%\">Ethernet1\/2<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Create Reference Addresses<\/h2>\n<p>Under <strong>Objects &gt; Addresses<\/strong>, click <strong>Add<\/strong>.<\/p>\n<figure id=\"attachment_380\" aria-describedby=\"caption-attachment-380\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-380 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT1.jpg\" alt=\"Add an address\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT1.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT1-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT1-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT1-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT1-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT1-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT1-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-380\" class=\"wp-caption-text\">Figure 1.56: Add an address<\/figcaption><\/figure>\n<p>In this window, we will add the IP of the WordPress server to reference it easier.<\/p>\n<figure id=\"attachment_176\" aria-describedby=\"caption-attachment-176\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-176 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-27-04-image.png\" alt=\"WordPress IP address\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-27-04-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-27-04-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-27-04-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-27-04-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-27-04-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-27-04-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-27-04-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-176\" class=\"wp-caption-text\">Figure 1.57: WordPress IP address<\/figcaption><\/figure>\n<p>We also want to put our firewall&#8217;s &#8220;public&#8221; IP (the interface facing the NAT cloud) here too. You can find the firewall&#8217;s DHCP address under <strong>network &gt; interfaces<\/strong>. Then click the hyperlink under IP address:<\/p>\n<figure id=\"attachment_364\" aria-describedby=\"caption-attachment-364\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-364 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9.jpg\" alt=\"Dynamic-DHCP Client IP address\" width=\"1024\" height=\"769\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9-300x225.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9-768x577.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9-65x49.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9-225x169.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/DHCP9-350x263.jpg 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-364\" class=\"wp-caption-text\">Figure 1.58: Dynamic-DHCP Client IP address<\/figcaption><\/figure>\n<p>From there you will find the IP address of the firewall:<\/p>\n<figure id=\"attachment_178\" aria-describedby=\"caption-attachment-178\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-178 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-30-12-image.png\" alt=\"Verify Dynamic-DHCP Client IP address\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-30-12-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-30-12-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-30-12-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-30-12-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-30-12-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-30-12-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-30-12-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-178\" class=\"wp-caption-text\">Figure 1.59: Verify Dynamic-DHCP Client IP address<\/figcaption><\/figure>\n<h2>Create a DNAT Policy<\/h2>\n<p>Under <strong>Policies &gt; NAT<\/strong>, click the Add button on the bottom.<\/p>\n<figure id=\"attachment_381\" aria-describedby=\"caption-attachment-381\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-381 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT2.jpg\" alt=\"Add a DNAT Policy\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT2.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT2-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT2-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT2-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT2-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT2-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT2-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-381\" class=\"wp-caption-text\">Figure 1.60: Add a DNAT Policy<\/figcaption><\/figure>\n<p>Under the Original Packet tab, configure these settings:<\/p>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\">\n<caption>Table 1.9: DNAT Configuration<\/caption>\n<tbody>\n<tr>\n<th style=\"width: 50%\" scope=\"col\">Parameters<\/th>\n<th style=\"width: 50%\" scope=\"col\">Value<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Source Zone<\/td>\n<td style=\"width: 50%\">Outside<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Destination Zone<\/td>\n<td style=\"width: 50%\">Outside<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Destination Interface<\/td>\n<td style=\"width: 50%\">any<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Service<\/td>\n<td style=\"width: 50%\">service-http<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Destination Address<\/td>\n<td style=\"width: 50%\">(Firewall Public Address Here)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<figure id=\"attachment_180\" aria-describedby=\"caption-attachment-180\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-180 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-42-34-image.png\" alt=\"DNAT Policy Rule- Original Packet\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-42-34-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-42-34-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-42-34-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-42-34-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-42-34-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-42-34-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-42-34-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-180\" class=\"wp-caption-text\">Figure 1.61: DNAT Policy Rule- Original Packet<\/figcaption><\/figure>\n<p>Under the translated packet tab, Destination Address Translation. Configure these:<\/p>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 61px\">\n<caption>Table 1.10: DNAT Translated Packet Configuration<\/caption>\n<tbody>\n<tr style=\"height: 15px\">\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Parameters<\/th>\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Value<\/th>\n<\/tr>\n<tr style=\"height: 16px\">\n<td style=\"width: 50%;height: 16px\">Translation Type<\/td>\n<td style=\"width: 50%;height: 16px\">Static IP<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Translated Address<\/td>\n<td style=\"width: 50%;height: 15px\">(IP of WordPress here)<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Translated Port<\/td>\n<td style=\"width: 50%;height: 15px\">80<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<figure id=\"attachment_181\" aria-describedby=\"caption-attachment-181\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-181 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-44-24-image.png\" alt=\"DNAT Policy Rule- Translated Packet\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-44-24-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-44-24-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-44-24-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-44-24-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-44-24-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-44-24-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-44-24-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-181\" class=\"wp-caption-text\">Figure 1.62: DNAT Policy Rule- Translated Packet<\/figcaption><\/figure>\n<p>Then, press <strong>OK<\/strong>.<\/p>\n<h1>Security Policy for DNAT<\/h1>\n<p>Under <strong>Policies &gt; Security<\/strong>. Click <strong>Add<\/strong> at the bottom.<\/p>\n<figure id=\"attachment_382\" aria-describedby=\"caption-attachment-382\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-382 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT3.jpg\" alt=\"Add a Security Policy\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT3.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT3-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT3-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT3-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT3-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT3-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/NAT3-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-382\" class=\"wp-caption-text\">Figure 1.63: Add a Security Policy<\/figcaption><\/figure>\n<p>Under the source tab, add the outside zone under the source zone:<\/p>\n<figure id=\"attachment_183\" aria-describedby=\"caption-attachment-183\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-183 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-15-image.png\" alt=\"Configuring the Source Zone\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-15-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-15-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-15-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-15-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-15-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-15-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-15-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-183\" class=\"wp-caption-text\">Figure 1.64: Configuring the Source Zone<\/figcaption><\/figure>\n<p>Under the destination tab, add the inside zone as the destination zone:<\/p>\n<figure id=\"attachment_184\" aria-describedby=\"caption-attachment-184\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-184 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-46-image.png\" alt=\"Configuring the Destination Zone\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-46-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-46-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-46-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-46-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-46-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-46-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-46-46-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-184\" class=\"wp-caption-text\">Figure 1.65: Configuring the Destination Zone<\/figcaption><\/figure>\n<p>After that press <strong>OK<\/strong>, then <strong>Commit<\/strong>.<\/p>\n<h2>Test DNAT<\/h2>\n<p>Using the Outside webterm. Navigate to the public IP address of your firewall. If any webpage shows up, whether it&#8217;s the WordPress site or the one below. You got DNAT working!<\/p>\n<figure id=\"attachment_185\" aria-describedby=\"caption-attachment-185\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-185 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-49-08-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-49-08-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-49-08-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-49-08-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-49-08-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-49-08-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-49-08-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-18-01-49-08-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-185\" class=\"wp-caption-text\">Figure 1.66: Verify your configuration<\/figcaption><\/figure>\n","protected":false},"author":1572,"menu_order":4,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-113","chapter","type-chapter","status-publish","hentry"],"part":3,"_links":{"self":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/113","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/users\/1572"}],"version-history":[{"count":25,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/113\/revisions"}],"predecessor-version":[{"id":1212,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/113\/revisions\/1212"}],"part":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/113\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/media?parent=113"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapter-type?post=113"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/contributor?post=113"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/license?post=113"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}