Read the following examples of NAT rules.
This guide provides the information you need to work with your Forcepoint product.
The SMC as a Service provides centralized access for configuring, managing, logging, and monitoring NGFWs that secure network connectivity and control business operations.
Policies are key elements that contain rules for allowing or blocking network traffic and inspecting the content of traffic.
Policy elements are containers for the rules that determine how Engines, Master Engines, and Virtual Engines examine traffic. The policy elements for the Engines include Template Policies, Policies, and Sub-Policies.
Access rules are lists of matching criteria and actions that define how the Engine treats different types of network traffic. They are your main configuration tool for defining which traffic is stopped and which traffic is allowed.
Network address translation (NAT) replaces the source or destination IP addresses in packets with other IP addresses. NAT rules define how NAT is applied to traffic.
Address translation is configured as part of the Engine Policy using NAT rules.
If NAT is needed between SMCaaS Application, you must define Contact Addresses for the communications so that the components use the correct address for contact when needed.
You can use NAT for outbound load-balancing.
Automatic proxy ARP requires an explicit route to the host or network to be configured in the Routing pane of the Engine Editor.
Protocols of the Protocol Agent type help with problems related to certain complex protocols and NAT.
These examples illustrate some common uses for NAT rules and the general steps on how each example is configured.
This example shows a static address translation that translates the addresses in one network to IP addresses in another network.
This example shows a dynamic address translation that translates the addresses in one internal network to a single external address for general web browsing.
This example shows a static address translation that translates the external IP address of a web server to the server’s internal address.
In this example, hairpin NAT is configured.
Inspection Policy elements define how the Engines look for patterns in traffic allowed through the Access rules and what happens when a certain type of pattern is found.