Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Block port on nat1nat

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 4 Posters 4.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      hamed_forum
      last edited by

      i create 1to1 nat for one public address .
      same local 192.168.1.12  public 20.20.20.18
      now i like block port 1433 on this 1to1 nat
      the user from wan cant access 20.20.20.18 by port 1433

      plz help me

      1 Reply Last reply Reply Quote 0
      • M Offline
        muswellhillbilly
        last edited by

        Why not simply port forward the ports to the service(s) on the internal host you want your WAN users to access?

        1 Reply Last reply Reply Quote 0
        • H Offline
          hamed_forum
          last edited by

          we have many public ip and all of the use 1to1 nat.its wronge?
          20.20.20.1  nat 192.168.1.11
          20.20.20.2 nat 192.168.1.12
          .
          ..
          .
          .
          .
          20.20.20.100  nat 192.168.1.100
          whats the best parctice?
          we have many site

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            "whats the best parctice?"

            Well the best practice if you have large publiic netblock would be to not NAT at all, why is this 20.20.20 segment you have just not routed to you..  If you want to run with the big dogs you need to learn to piss in the tall weeds ;)

            Ie if you want to play like a service provider/ colo, etc.  Then why would you be natting this traffic?  If your going to nat an only want to allow specific ports then port forwarding would be the way to go..

            Are these boxes yours on the 192 address space, or are they paying customers of yours?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.11 | Lab VMs 2.8.1, 25.11

            1 Reply Last reply Reply Quote 0
            • C Offline
              cmb
              last edited by

              You don't want to block any specific ports inbound, you should only be allowing the minimal things on WAN that are required, and everything else hits the default deny. If you have any rules permissive enough to allow everything in on WAN, you're doing it wrong. Use a restrictive WAN ruleset.

              1 Reply Last reply Reply Quote 0
              • H Offline
                hamed_forum
                last edited by


                we have same topology
                i nat1nat to all server .you say i find the sever need witch service need same http port 80
                and in portforwader write role?
                sorry for bad engishe

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.