7.3.2. Translation of Multiple IP
Addresses (M:N)
Create an address object for the public IP address:
1.
Go to Objects > Address Book > Add > IP address
2.
Specify a suitable name for the object, for example wwwsrv_pub
3.
Enter 195.55.66.77 - 195.55.66.77.81 as the IP Address
4.
Click OK
Now, create another address object for the base of the web server IP addresses:
1.
Go to Objects > Address Book > Add > IP address
2.
Specify a suitable name for the object, for example wwwsrv_priv_base
3.
Enter 10.10.10.5 as the IP Address
4.
Click OK
Publish the public addresses on the wan interface using ARP publish. One ARP item is needed for every IP
address:
1.
Go to Interfaces > ARP > Add > ARP
2.
Now enter:
•
Mode: Publish
•
Interface: wan
•
IP Address: 195.55.66.77
3.
Click OK and repeat for all 5 public IP addresses
Create a SAT rule for the translation:
1.
Go to Rules > IP Rules > Add > IPRule
2.
Specify a suitable name for the rule, for example SAT_HTTP_To_DMZ
3.
Now enter:
•
Action: SAT
•
Servce: http
•
Source Interface:any
•
Source Network: all-nets
•
Destination Interface: wan
•
Destination Network: wwwsrv_pub
4.
Switch to the SAT tab
5.
Make sure that the Destination IP Address option is selected
6.
In the New IP Address dropdown list, select wwwsrv_priv
7.
Click OK
Finally, create a corresponding Allow Rule:
1.
Go to Rules > IP Rules > Add > IPRule
2.
Specify a suitable name for the rule, for example Allow_HTTP_To_DMZ
3.
Now enter:
•
Action: Allow
•
Service: http
296
Chapter 7. Address Translation