Hot!Explicit Proxy Policy with outgoing NAT

Author
cmoro
New Member
  • Total Posts : 9
  • Scores: 0
  • Reward points: 0
  • Joined: 2017/03/08 00:49:31
  • Status: offline
2017/03/08 01:53:38 (permalink) 5.4
0

Explicit Proxy Policy with outgoing NAT

Hello forum,
 
is it possible to configure Explicit Proxy Policy and use a different outgoing IP address as one that is configured for WAN Interface? Unfortunately I cannot see any NAT option within Exp Proxy Policy.
 
For example - WAN Primary IP 1.1.1.1/24, Secondary IP 2.2.2.2/24
 
Exp. Proxy Policy use the IP 1.1.1.1 as the source IP address. I would like to change it to 2.2.2.3 for instance. It works correctly with regular IPv4 Policy where I am able to use a dynamic IP Pool and control the NATed source IP address of the outgoing traffic to the Internet.
 
Thank you advance for any hint.
 
Jozef
#1

7 Replies Related Threads

    cmoro
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2017/03/08 00:49:31
    • Status: offline
    Re: Explicit Proxy Policy with outgoing NAT 2017/03/10 04:30:34 (permalink)
    0
    To answer to my question, it is possible to configure outgoing IP (WAN Secondary IP in my case) for Explicit Web/FTP Proxy.
     
    # config web-proxy explicit
    (explicit) # set outgoing-ip ?      Outgoing HTTP requests will leave this IP. An interface must have this IP address.
    #2
    ravikumarv
    New Member
    • Total Posts : 2
    • Scores: 0
    • Reward points: 0
    • Joined: 2016/11/23 00:04:47
    • Status: offline
    Re: Explicit Proxy Policy with outgoing NAT 2017/04/26 01:21:26 (permalink)
    0
    Hi,
        I am also facing the same issue. Is there any solution to configure NAT in web proxy policy?
     
    Thanks 
    Ravi
     
    #3
    cmoro
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2017/03/08 00:49:31
    • Status: offline
    Re: Explicit Proxy Policy with outgoing NAT 2017/04/26 04:00:56 (permalink)
    0
    Take a look at my last post. You can specify an outgoing IP for Web Explicit Proxy.
    #4
    AtiT
    Platinum Member
    • Total Posts : 473
    • Scores: 42
    • Reward points: 0
    • Joined: 2012/04/18 12:13:27
    • Location: Prague / Czech Republic
    • Status: offline
    Re: Explicit Proxy Policy with outgoing NAT 2018/10/29 09:45:39 (permalink)
    0
    Hello,
    Is it possible to NAT traffic to another IP address than the interface address?
    I need to NAT some subnets and IPs to another IP address than the interface but the communication is broken. I set an IP Pool object under the explicit policy (OS version 5.6.5). I also tried to add the IP Pool address as a secondary address on the outgoing interface but without success.

    AtiT
    --------------------
    NSE 8, CCNP R+S
    #5
    emnoc
    Expert Member
    • Total Posts : 5622
    • Scores: 357
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: Explicit Proxy Policy with outgoing NAT 2018/10/30 08:21:52 (permalink)
    0
    Yes as indicated  earlier you can change the outgoing interface.
       http://socpuppet.blogspot.com/2017/08/turn-around-explicit-proxy-on.html
     
     

    PCNSE 
    NSE 
    StrongSwan  
    #6
    SMGK74
    New Member
    • Total Posts : 2
    • Scores: 0
    • Reward points: 0
    • Joined: 2016/02/15 14:07:52
    • Status: offline
    Re: Explicit Proxy Policy with outgoing NAT 2020/04/09 00:07:17 (permalink)
    0
    There is another way: you can also use a ippool nat in the explicit web proxy policy but only by cli:
     
     
    config firewall proxy-policy
    edit {policyid}
    set poolname {name IP pool name}
    next
    end
     
    Ciao
     
    Sergio
     
     
     
     
    #7
    emnoc
    Expert Member
    • Total Posts : 5622
    • Scores: 357
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: Explicit Proxy Policy with outgoing NAT 2020/04/09 07:15:32 (permalink)

    PCNSE 
    NSE 
    StrongSwan  
    #8
    Jump to:
    © 2020 APG vNext Commercial Version 5.5