{"id":1779,"date":"2020-09-02T14:24:33","date_gmt":"2020-09-02T14:24:33","guid":{"rendered":"https:\/\/partnernews.sophos.com\/fr-fr\/?p=1779"},"modified":"2020-09-02T14:24:33","modified_gmt":"2020-09-02T14:24:33","slug":"comment-exploiter-au-maximum-xg-firewall-v18-5eme-partie","status":"publish","type":"post","link":"https:\/\/partnernews.sophos.com\/fr-fr\/2020\/09\/products\/comment-exploiter-au-maximum-xg-firewall-v18-5eme-partie\/","title":{"rendered":"Comment exploiter au maximum XG Firewall\u00a0v18\u00a0: 5\u00e8me\u00a0Partie"},"content":{"rendered":"<p>Quiconque a d\u00e9j\u00e0 essay\u00e9 de configurer des r\u00e8gles NAT (Network Address Translation) sait \u00e0 quel point cette t\u00e2che peut s\u2019av\u00e9rer difficile alors qu\u2019il existe une mani\u00e8re tr\u00e8s simple d\u2019y parvenir. XG Firewall int\u00e8gre une toute nouvelle fonctionnalit\u00e9 NAT puissante et intuitive d\u00e9di\u00e9e au NAT source (SNAT), au NAT de destination (DNAT) ainsi qu\u2019\u00e0 d\u2019autres t\u00e2ches de traduction r\u00e9seau qui simplifient v\u00e9ritablement le m\u00e9canisme NAT.\u00a0 Les nouvelles r\u00e8gles NAT se trouvent au niveau de l\u2019\u00e9cran \u2018R\u00e8gles et strat\u00e9gies\u2019.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1840 size-full\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/001-NAT-rules.png\" alt=\"\" width=\"830\" height=\"386\" \/><\/p>\n<p>There are a few different types of address translation tasks that are covered by the new NAT rules in XG Firewall v18:<\/p>\n<ul>\n<li><strong>Source Network Address Translation<\/strong> (or SNAT) translates internal private IP addresses to a public IP address, dramatically reducing the consumption of public IP addresses which have now been exhausted.<\/li>\n<li><strong>Destination Network Address Translation<\/strong> (or DNAT) or port forwarding is commonly used to publish a service located on the private network to the publicly accessible IP address. Port Address Translation or PAT is a subset of DNAT that translates private IP addresses to the public IP address via port numbers.<\/li>\n<li><strong>NAT hairpinning<\/strong>, or loopback or NAT reflection is a combination of address translation that permits access of a service via the public IP address from inside the private network thus facilitating two-way communication via the public IP address and simplifying domain name resolution.<\/li>\n<\/ul>\n<p><strong>NAT Migration from Previous Versions<br \/>\n<\/strong>Those familiar with NAT in previous versions of XG Firewall will know SNAT was bound to firewall rules, and DNAT was combined with WAF in creating business application rules.\u00a0 In XG Firewall v18, all NAT rules are now together in the new NAT rules tab providing much better visibility and a more intuitive set of tools to build more powerful and flexible NAT rules.\u00a0 Linked NAT and firewall rules are still supported for those who prefer that model, but we strongly encourage you to explore the benefits of the new NAT rule scheme and the tools provided.<\/p>\n<p>In order to maintain compatibility, when you upgrade to v18 from previous versions of XG Firewall, you will find several NAT rules have been created automatically.\u00a0 In fact, there will be one new SNAT rule created and linked to each firewall rule that was previously using masquerading (MASQ), and one DNAT rule for each business application rule.<\/p>\n<p>Depending on your previous NAT utilization and firewall rule structure, many of the SNAT rules for LAN to WAN traffic may now be redundant.\u00a0 The firewall is unable to consolidate these rules automatically to ensure compatibility, but you can certainly consolidate them manually.\u00a0 Simply delete any unnecessary redundant NAT rules as long as you have one matching rule at the bottom of the rule list that will catch all firewall matching criteria necessary.\u00a0 Take advantage of the new filter and sort options available to help with migration housekeeping by looking at all Linked NAT rules that were created during migration.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1838 size-full\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/002-NAT-Rules.png\" alt=\"\" width=\"830\" height=\"300\" \/><\/p>\n<p><strong>Making the Most of NAT in XG Firewall v18<br \/>\n<\/strong>The new NAT capabilities are both powerful and easy to use.\u00a0 For example, creating a port forwarding or DNAT rule has never been easier, thanks to the new Server Access Assistant Wizard.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1839 size-full\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/003-NAT-Rules.png\" alt=\"\" width=\"830\" height=\"210\" \/><\/p>\n<p>You just need to provide a few vital pieces of information such as the internal host, the services, and the external access criteria and the wizard will take care of the rest, creating the necessary NAT rules for you.<\/p>\n<p>To learn more about how to make the most of the new NAT rules in XG Firewall v18 watch this helpful how-to video which is also conveniently linked right from the top of the NAT rules screen in the product.<\/p>\n<p>Here\u2019s a summary of the resources available to help you make the most of the new features in XG Firewall v18:<\/p>\n<figure id=\"attachment_1827\" aria-describedby=\"caption-attachment-1827\" style=\"width: 300px\" class=\"wp-caption alignright\"><a href=\"https:\/\/partnernews.sophos.com\/en-us\/?s=%22Making+the+Most+of+XG+Firewall+v18%22\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1827 size-full\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/XG-series-1.png\" alt=\"\" width=\"300\" height=\"300\" \/><\/a><figcaption id=\"caption-attachment-1827\" class=\"wp-caption-text\">Read the rest of the series<\/figcaption><\/figure>\n<ul>\n<li><a href=\"https:\/\/docs.sophos.com\/nsg\/sophos-firewall\/18.0\/Help\/en-us\/webhelp\/startup\/nsg\/sfos\/concepts\/ControlCenterOverview.html\" target=\"_blank\" rel=\"noopener noreferrer\">XG Firewall getting started guide<\/a><\/li>\n<li><a href=\"https:\/\/docs.sophos.com\/nsg\/sophos-firewall\/18.0\/Help\/en-us\/webhelp\/onlinehelp\/index.html\" target=\"_blank\" rel=\"noopener noreferrer\">Full online XG Firewall documentation<\/a><\/li>\n<li><a href=\"https:\/\/www.sophos.com\/en-us\/support\/products\/xg-firewall\/how-to-library.aspx#newVersion\" target=\"_blank\" rel=\"noopener noreferrer\">How-to videos on what\u2019s new in v18<\/a><\/li>\n<li><a href=\"https:\/\/community.sophos.com\/products\/xg-firewall\/f\/recommended-reads\" target=\"_blank\" rel=\"noopener noreferrer\">A full list of recommended community articles on v18<\/a><\/li>\n<\/ul>\n<p>If you\u2019re new to Sophos XG Firewall, <a href=\"https:\/\/www.sophos.com\/en-us\/products\/next-gen-firewall.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">learn more<\/a> about the great benefits and features XG Firewall can deliver to your network.<\/p>\n<p><strong>Selling XG Firewall<\/strong><br \/>\nOn the Sophos partner portal, we provide you with a wealth of\u00a0<a href=\"https:\/\/partners.sophos.com\/prm\/English\/s\/assets?collectionId=10929\" target=\"_blank\" rel=\"noopener noreferrer\">sales assets<\/a>. You may filter the list of assets by selecting a category to narrow down the results. And don\u2019t forget to check whether there is a\u00a0<a href=\"https:\/\/partners.sophos.com\/prm\/English\/s\/assets?collectionId=10956\" target=\"_blank\" rel=\"noopener noreferrer\">sales promotion<\/a>\u00a0available for your region. It\u2019s worth checking back from time to time to make sure you\u2019re not missing out on a great opportunity!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Quiconque a d\u00e9j\u00e0 essay\u00e9 de configurer des r\u00e8gles NAT (Network Address Translation) sait \u00e0 quel point cette t\u00e2che peut s\u2019av\u00e9rer difficile alors qu\u2019il existe une mani\u00e8re tr\u00e8s simple d\u2019y parvenir.<\/p>\n","protected":false},"author":19,"featured_media":300000607,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[74],"tags":[26],"coauthors":[45],"class_list":["post-1779","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-products","tag-xg-firewall"],"jetpack_featured_media_url":"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/02\/xg-firewall-v18-1600x-960-horizontal.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/wp\/v2\/posts\/1779","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/wp\/v2\/comments?post=1779"}],"version-history":[{"count":1,"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/wp\/v2\/posts\/1779\/revisions"}],"predecessor-version":[{"id":1781,"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/wp\/v2\/posts\/1779\/revisions\/1781"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/wp\/v2\/media?parent=1779"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/wp\/v2\/categories?post=1779"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/wp\/v2\/tags?post=1779"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/fr-fr\/wp-json\/wp\/v2\/coauthors?post=1779"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}