Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Blason_R
Leader
Leader

How do I NAT multiple hosts on port 443 or80 behind cloud guard azure firewall?

Hi Team,

 

As a standard practice I am deploying vsec firewall in Azure with 1 Vnet and 4 subnets

10.1.1.0/24 Frontend

10.1.2.0/24 backend

10.1.3.0/24 Web Servers

What I understood from documents is 

I need to put a route for 10.1.3.0 on Firewall and define UDR on Azure portal for outbound traffic. Now since I have around 4 web servers in 10.1.3.x network; I guess we are natting all those servers behind 10.1.1.x subnet or behind firewall IP address.

In this case my original destination would 10.1.1.10 [Firewall external IP] and xlate destination IP is 10.1.3.10 [web server]

If the next server then can I use 10.1.1.20:443 [virtual IP from pool] and nat with 10.1.3.20:443 by adding proxy arp for 10.1.1.20 on firewall?

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
5 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.