I had to reconfigure a FG301B in NAT mode this morning. My first. We have about 50 FGs in operation, but they' re all in transparent mode bethind Cisco Pix firewalls. Since there was no Pix at the site I visited this morning, I opted to reconfigure the FG in NAT mode.
I looked for the equivalent of PAT on the IP of the outside interface, but couldn' t find it. I fiddled around with the Virtual IP component (Firewall > Virtual IP) and the Central NAT Table (Firewall > Policy > Central NAT Table) but couldn' t figure it out.
I finally just configured a policy and selcted " NAT" for the outbound policy and configured everything else pertty much as I had on all the other FGs in transparent mode. Much to my surprise, it worked.
I' d really like someone to explain what' s going on, though. Is the FG running PAT on the IP of the outside interface now? I didn' t define a pool of addresses to run NAT on. We always do PAT on the IP of the outside interface on the Pixes. And what' s the Virtual IP component for, exactly?
Chris Rowan
Instructional Technology
Brownsville ISD
Brownsville, TX