Configuration Guide# How to Configure Basic SNAT Policy
  

Sangfor Jojo Lv5Posted 14 Nov 2023 10:54

Product: NGAF
Version: 8.0.47

1. Introduction
1.1 Scenario
In a typical small Enterprise Network, internal users or LAN users must have access outside or what we call the “Internet”. An example of this is a user that is using Google Services like Gmail or a user that needs to have access to social media platforms like Facebook or Twitter etc.
In this article, I will show you how to configure an SNAT (Source Network Address Translation) policy on the Sangfor NGAF. SNAT will translate the internal IP to the public IP. This is to allow internal users to access the internet.
图片1.png

1.2 Prerequisites
1) Two Zones must be created, theLAN and WAN Zone.
2) The interface eth2 is in the WAN Zone
3) The interface eth3 is in the LAN Zone
4) The interface eth2 must have the “WAN attributes” check just like the image below:
图片2.png

<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<

2. Configuration Guide
2.1 NGAF Configuration
Step 1.
Go to Policies > NAT > IPv4 NAT and click Add, as shown below:
图片3.png
Step 2. A new window will pop up when you click the Add Button. Then put the following details:
1) Descrtiption: Aggregate Link to Core Switch
2) Type: Source NAT
3) Name: Basic_SNAT
4) Description: NAT Policy for the internal users to access the internet
5) Original Data Packet
-Src Zone: LAN
-Src Address: Private Network Segment
-Dst Zone/interface: WAN
-Dst Address: All
6) Translated Data Packet
Translate Src IP To: Outbound Interface
Then click Save.
图片4.png
Note: Under the “Src Address” I choose “Private Network Segment since LAN users are using Private IP Addresses but it can be specified by creating an Object.

Step 3. Verify the newly created IPv4 NAT Policy:
图片5.png

Step 4. Verify if the users can access the internet
图片6.png

<<<<<<<<<<<<<<<<<<<<<<<<<< <<<<<<<<<<<<<<<<<<<<<<<<<< <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<

3. Precaution
1. For this SNAT Policy to work, there should be at least Access Control configured with the action “Allow” just like the image below:
图片7.png

--------------------------------------------- This article is contributed by    ----------------------------

01.png

Wanna get to know him? Click here.

Like this topic? Like it or reward the author.

Creating a topic earns you 5 coins. A featured or excellent topic earns you more coins. What is Coin?

Enter your mobile phone number and company name for better service. Go

Sangfor Jojo Lv5Posted 14 Nov 2023 14:42
  
We warmly welcome engineers to share your creations like configuration guides or troubleshooting cases with us. Each article will be rewarded with at least 4000 coins.