Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Askey_oot
Contributor
Jump to solution

separate services to specific interface

Hi All,

We have an ip public range from our service provider. We want to configure separate connection on port DMZ to our specific service. I have an diagram. It's possible to configure it?

 

ss2.png

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

On SMB appliances, Port Forwarding is generally handled through Server objects.
It's not clear to me how traffic would be forwarded OUT the WAN interface and come back to the DMZ interface, particularly if the .189 address is on the same subnet as your DMZ interface.

Which means you have a hairpin NAT situation. 
Server objects have a "Force translated traffic to return to the gateway" option to address this specific situation.
This will impact ALL traffic that hits this server object (not just internally sourced).

image.png

View solution in original post

2 Replies
PhoneBoy
Admin
Admin

On SMB appliances, Port Forwarding is generally handled through Server objects.
It's not clear to me how traffic would be forwarded OUT the WAN interface and come back to the DMZ interface, particularly if the .189 address is on the same subnet as your DMZ interface.

Which means you have a hairpin NAT situation. 
Server objects have a "Force translated traffic to return to the gateway" option to address this specific situation.
This will impact ALL traffic that hits this server object (not just internally sourced).

image.png

the_rock
MVP Platinum
MVP Platinum

Maybe you can verify with TAC to be sure, but what @PhoneBoy said all makes sense.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events