Block of 8 public IP addresses - can I pick and choose which IP maps to a port?
a4g_inatl1
Posts: 2
in Security
I have
- a low volume email and web server.
- a USG20 VPN device in a small home/office scenario.
- a block of 8 public IP addresses, 5 usable with mask 255.255.255.248. These have been in use for years.
I plan to shutdown my current old server and have created a new email server and will separate the web server next onto it own server.
My intentions are to separate/use 2 of the IP's and use map/NAT/other way to target IP (example 192.168.200.3 and 192.168.201.5), using 2 different ports (4 and 5 on the device) for the mail and web servers. This is for security purposes. I have 1 IP for Mail and another for web.
I would probably use NAT to redirect each public or NATted IP to the port number
Questions:
- Is it necessary to use 2 ports?
- Is NAT the best way to separate the IP's?
- Do I need to use NAT or can I direct the mail and web public IP's directly to the ports on the device?
TIA, Darryl.
0
All Replies
-
- You can set virtual server or 1:1 NAT instead of 2 ports, Firewall will respond ARP of other public IP in this case.
- I believe it is the best way that only open necessary ports by NAT, moreover firewall can prevent some attack from internet.
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight