How to configure SonicWall inbound NAT

  Рет қаралды 17,505

Jean-Pier Talbot

Jean-Pier Talbot

Күн бұрын

Пікірлер: 54
@66Blackula66
@66Blackula66 2 жыл бұрын
May be interesting for some people: Instead of setting up the hardened rule to allow access from a fixed WAN ip/source only, you could also use a fqdn for the source in combination with e.g dyndns or any other dynip dns service. Works like a charm...
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Smart! I like it. Just be careful as some carrier (especially cell phone carrier) will share an IP with many many many other customers. But still 1000x better than opening it to « any »! Thanks. Haven’t thought about it
@PersianSoheil
@PersianSoheil 10 ай бұрын
thanks for the video. I was pulling my hair out of my skill to figure this out on my own.
@udirt
@udirt 9 ай бұрын
Hey Jean-Pier - ty, your video has helped me twice already. the thing with the WAN IP in the rule destination - honestly i like the logic behind it, but it's just opposite of what you have in other firewalls and i almost never work on sonicwalls, but when i do they're someone else's and full of unnamed rules. it's tedious to find the issue but - thank you - i fimally got my vpn connect going. (natting to 'my' network zone's firewall)
@LuizHicke
@LuizHicke 2 жыл бұрын
Pretty cool tips to make NAT security. Thanks for sharing and help us J-P.
@MHALAPOW
@MHALAPOW 2 жыл бұрын
Thanks, waiting for harden configuration video.
@gabrielti9570
@gabrielti9570 2 жыл бұрын
Hi Jean, great videos! I am from Brazil, and your videos help me a lot. Please consider making a video on how to make and configure a DMZ. Thanks!!!
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Hi Gabriel! Thanks for the feedback. I can surely make a video on DMZ. I already have a few videos lined up. I’ll add it to the list! Thanks
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Actually I believe I have done it. Look at my « network segregation » video. Pretty sure I show how to create a DMZ. Have a look and let me know :-)
@eduardoorta6745
@eduardoorta6745 2 жыл бұрын
Muchas Gracias Jean!!!
@moviesworld5810
@moviesworld5810 2 жыл бұрын
Thank you so much bro. 👍
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
My pleasure!
@preciousclips3006
@preciousclips3006 10 ай бұрын
Hello, on video you are saying to fix DNS rather than band-aid like NAT Policy. However, is there way to set loopback policy only through DNS Server? no matter how hard I search for it, only I can find that port forwarding can be only by router not by DNS Server. If there is way to do that, please walk it through.
@techtalksothers
@techtalksothers Жыл бұрын
Awesome!
@BlueMoonTechnologies-x4x
@BlueMoonTechnologies-x4x Ай бұрын
Jean-Pier, I have an interesting situation where my client's TZ570 is behind the buildings nat and getting a dhcp class c Ip address from their firewall. what I'm l'm needing to accomplish is allowing outside users access to an internal source. in this instance a file server. what are your thoughts
@JeanPierTalbot
@JeanPierTalbot Ай бұрын
That won’t work. Unless you get the first firewall to NAT to your firewall then you can NAT it yourself. But really not optimal. Best would be to get your own internet.
@ahirnimesh09
@ahirnimesh09 2 жыл бұрын
please make video on application policies in sonicwall.
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Ok, it´s next in line :-)
@verticostate
@verticostate 11 ай бұрын
Hi Jean-Pier. I heard you mentioned that your Playstation is in your IOT-Zone. Did you manage to get it to NAT Type 2 using you Sonicwall for online play? Mine is Strict (Nat Type 3) and I'm struggling with the NAT Policies.
@JeanPierTalbot
@JeanPierTalbot 11 ай бұрын
I dont play with it. Kid and GF does. They don’t complain :-) PS4 is accessing internet just line any other devices through default NaT policies
@thomasg.8198
@thomasg.8198 Жыл бұрын
How to put only on host in a DNS zone, while the other hosts of the DNS zone is managed outside the LAN?
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
You will need an access rule that allows DNS from the lan to the dns zone
@ppoo92
@ppoo92 Жыл бұрын
Hello, I just stumbled across your video. I was wondering if you could provide some insights on port forwarding on a Sonicwall. I am trying to pass a live stream from my phone to my home PC that is running OBS then send that out to a internet streaming service such as KZbin or Twitch.
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
Good one. I don’t know the requirements for what you are trying to achieve or event if it’s possible. I won’t be able to help on this one
@tweedy151
@tweedy151 8 ай бұрын
it always confuses me on Sonicwalls, why NAT rules also require firewall rules and vice versa? Can you gain access from external with just a NAT rule? Or what would happen if you created just a firewall rule right through to the destination, would that work? Why are firewall rules not just NAT enabled? They used to be on old Sonicwalls years ago like the SOHO etc.
@JeanPierTalbot
@JeanPierTalbot 7 ай бұрын
Agreed, it’s odd to do 2 policies for one thing. Doug Demuro would call that « quirks and features » :-)
@waynedubose8509
@waynedubose8509 Жыл бұрын
@JeanPierTalbot Is there any way for the user authentication method work if I use an IP address from a block of public addresses we have instead of the actual WAN Interface IP address?
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
Yes you can use other Wan IP you have too
@waynedubose8509
@waynedubose8509 Жыл бұрын
@@JeanPierTalbot What I am trying to do is allow a remote non SSLVPN user to access resources across our site-to-site VPN. I am allowing this now, but the users are SSLVPN users that get assigned an inside address. Using the method discussed here, is that possible?
@syedashraf7209
@syedashraf7209 Жыл бұрын
Hi sir, i have a firewall with router based. There is a pc with port forwarding if i connect the pc with router the port forwarding is working when ever i connect the pc through firewall the port forwarding is not working i have allowed all the traffic also specified the traffic given free flow rules between router and firewall. may i know what might be the issue and needing solutions.
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
Hi Syed, Unfortunately I don’t know what it can be. It can be several things. Best would be to contact sonicwall tech support and provide them a diagram of what you are trying to achieve. They should be able to help.
@nicolasevrard6374
@nicolasevrard6374 2 жыл бұрын
Hello, I configured NAT on the sonicwall and the connection works from a remote network connected by VPN. However, I cannot connect to the sonicwall interface from this remote network. Access to the sonicwall interface is impossible through NAT ?
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Il not sure il following you. You are outside and want to nat yourself in to manage the firewall? I would advice to manage it from its wan or interface instead. Let me know if I’m off track :-)
@nicolasevrard6374
@nicolasevrard6374 2 жыл бұрын
@@JeanPierTalbot thank you for the feedback. I want to connect to the firewall from my remote network connected in VPN. From a remote network connected in VPN without NAT it works, but from a remote network connected with NAT it does not work. To access a local server from my remote network it works through NAT, but not firewall access. NAT is configured on the local firewall, not on the remote firewall. Sorry, I'm French, my English is not perfect
@pipi_delina
@pipi_delina 2 жыл бұрын
How can I make a nat pool for outbound NAT... on Sonicwall....
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
I never tried it, but I believe you simply use an address group that contains all the IP you want in the pool. Again, I haven’t tried it :-)
@pipi_delina
@pipi_delina 2 жыл бұрын
@@JeanPierTalbot I have a couple of IPs that maybe if someone wants to browse they can use. That's the use case I want to implement
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
@@pipi_delina and you want the user to be able to decide which WAN IP he wants to use? if so, you would need to create users, like user "WAN-IP-1" and create NAT policies to nat "WAN-IP-1" using your 1st WAN IP. then NAT policy for user "WAN-IP-2" using your 2st WAN IP. then you tell user to authenticate to the firewall as user "WAN-IP-1"
@pipi_delina
@pipi_delina 2 жыл бұрын
@@JeanPierTalbot it was a use case I wanted.. I achieved that by making group objects and used the group for the nat
@ManishKumar-vk5fl
@ManishKumar-vk5fl 2 жыл бұрын
Hi jean Thanks for such an informative videos can you please guide me how can i allow port forwarding if my firewall is installed behind the Cisco router I have a Scenario like >>ISP>>>Cisco router>>>TZ370>>>LAN
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Remove the Cisco? :-)
@lossco
@lossco 10 ай бұрын
your videos are amazing and I think I watched all multiple times. Anyway now I have a problem with a NSa2700. I cannot connect from outside to a webserver on port 80. Something is blocking 80 and 443. Need help pls
@JeanPierTalbot
@JeanPierTalbot 10 ай бұрын
Thanks! Some ISP are blocking those ports as they don’t want you to host anything. They want you to pay for their hosting services. Have a look at my NAT video. Try taking a weird port (like 555) and change the port in the NAT FOR 80. Original destination port: 555 Translated destination port: 80
@lossco
@lossco 9 ай бұрын
Thank you for the tips, at the end of the day was the gateway security and the packet inspector that block the inbound traffic on that ports. Put the workstation in an exclusion group and everything works now @@JeanPierTalbot
@averageChoom
@averageChoom 2 жыл бұрын
what can i get from a sonicwall tz270 with just the hardware with no licenses?
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
You won’t get any of the security features (IPS, antivirus, URL filtering…) and no support, no warranty, no OS upgrades. You won’t get any on the stuff mention here: www.sonicwall.com/products/firewalls/security-services/security-bundles/ I think over 90% of sales are with the security features. Highly recommended for security
@averageChoom
@averageChoom 2 жыл бұрын
@@JeanPierTalbot thank you you're videos are a huge help
@nampv
@nampv 2 жыл бұрын
NAT. how can the client's wan ip be logged in the app's log instead of the sonicwall's ip WAN
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Hi, sorry I’ll need more details. I don’t understand your question. Maybe it’s because it’s Friday and it has been a long week :-)
@nampv
@nampv 2 жыл бұрын
I want to record the user's ip address when they access rather than sonicwall's wan ip. After I've nat port . Sorry my english is so bad
@rudranarayanbiswal9853
@rudranarayanbiswal9853 2 жыл бұрын
Dear.... can you please provide the video for site to site VPN, where one site will have public IP. please explain step by step.... do not skip any step please
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Sure! Sounds like an easy one. But I have a few lined up already.
@jerryjones1767
@jerryjones1767 Жыл бұрын
Hi can you make a Video how to configure sonicwall for voip FreePBX rules WAN-Lan
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
I run trixbox for my sonicwall phone numbers. I use iax2 protocol with my cloud voip provider which is NAT friendly. I don’t know how to securely handle voip phone outside and open ports from the outside so they can reach the PBX inside. Especially if you are using SIP as it used 20 000+ ports and does not like NAT. You can reach out to your local sonicwall team, they can put you in touch with a local sonicwall partner that does professional services ($)
SonicWall switches - Basic step by step configuration
57:08
Jean-Pier Talbot
Рет қаралды 13 М.
JP's 4 basic security tips and tricks for your firewall
13:07
Jean-Pier Talbot
Рет қаралды 12 М.
Что-что Мурсдей говорит? 💭 #симбочка #симба #мурсдей
00:19
How to configure SonicWall client SSL VPN
11:41
Jean-Pier Talbot
Рет қаралды 42 М.
How to configure SonicWall Intrusion Prevention Service (IPS)
11:38
Jean-Pier Talbot
Рет қаралды 10 М.
How to configure site to site VPN
45:12
Jean-Pier Talbot
Рет қаралды 22 М.
How to configure SonicWall Content Filtering Service (CFS)
1:07:35
Jean-Pier Talbot
Рет қаралды 32 М.
SonicWall basic configuration step by step (part 1)
31:27
Jean-Pier Talbot
Рет қаралды 161 М.
Customer's firewall configuration review (first pass)
1:40:07
Jean-Pier Talbot
Рет қаралды 10 М.
How to configure SonicWall Single Sign On (SSO)
51:15
Jean-Pier Talbot
Рет қаралды 15 М.
What is Capture ATP and how to configure it
29:12
Jean-Pier Talbot
Рет қаралды 4,8 М.
How to configure SonicWall DPI-SSL
25:10
Jean-Pier Talbot
Рет қаралды 17 М.
How to configure Inter-VPN and SSL VPN routing
38:45
Jean-Pier Talbot
Рет қаралды 6 М.
Что-что Мурсдей говорит? 💭 #симбочка #симба #мурсдей
00:19