Firewall
Firewall and NAT Rule Configuration Examples
Firewall and NAT Rule Configuration Examples
STEP 1
STEP 2
Cisco ISA500 Series Integrated Security Appliances Administration Guide
Translated Source
Address
Translated
Destination Address
Translated Services
This section provides some configuration examples on adding firewall and NAT
rules.
•
Allowing Inbound Traffic Using the WAN IP Address, page 226
•
Allowing Inbound Traffic Using a Public IP Address, page 228
•
Allowing Inbound Traffic from Specified Range of Outside Hosts,
page 231
•
Blocking Outbound Traffic by Schedule and IP Address Range,
page 232
•
Blocking Outbound Traffic to an Offsite Mail Server, page 232
Allowing Inbound Traffic Using the WAN IP Address
Use Case: You host a FTP server on your LAN. You want to open the FTP server to
Internet by using the IP address of the WAN1 port. Inbound traffic is addressed to
your WAN1 IP address but is directed to the FTP server.
Solution: Perform the following tasks to complete the configuration:
Go to the Networking > Address Management page to create a host address
object with the IP 192. 1 68.75. 1 00 called "InternalFTP."
Go to the Firewall > NAT > Port Forwarding page to create a port forwarding rule
as follows.
WAN1_IP
FTPServer
FTP-CONTROL
6
226