This is the mirror policy for the one created in the previous section when you check Create a reflective policy. It allows you to translate an external public IP addresses into an internal private IP address. This NAT policy, when paired with a ‘permit’ access policy, allows any source to connect to the internal server using the public IP address; the SonicWall security appliance handles the translation between the private and public address. With this policy in place, the SonicWall security appliance translates the server’s public IP address to the private IP address when connection requests arrive via the WAN interface (by default, the X1 interface).
Go to the Firewall > Access Rules page and choose the policy for the ‘WAN’ to ‘Sales’ zone intersection (or, whatever zone you put your server in). Click on the ‘Add…’ button to bring up the pop-up access policy screen. When the pop-up appears, enter in the following values:
•
|
Action—Allow
|
•
|
Service—HTTP
|
•
|
Source—Any
|
•
|
Destination—Webserver_public_ip
|
•
|
Users Allowed—All
|
•
|
Schedule—Always on
|
•
|
Logging—Checked
|
•
|
Comment—(Enter a short description)
|