is NAT dynamic and/or 1-to-1 needed for a HTTP proxy rule ? M295

I have a HTTP-proxy rule on port 80 and I am wondering if I need the NAT enabled in the Advanced → NAT part of the configuration

I have Win PC on internal lan that seldom need to connect to HTTP web on outside/public web

My understanding is that the proxy will connect to the outside web using the public IP of the M295, so, NAT should not be enabled

right ?

Answers

  • Bruce_Briggs
    edited July 22

    Use NAT loopback to allow an internal device to access an internal web server using its public IP addr.

    About NAT Loopback

    https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/nat/nat_loopback_c.html

  • That's my understanding as well. For outbound HTTP traffic from an internal client through an HTTP proxy policy, the firewall will use its external interface to establish the connection, so you generally don't need to configure 1-to-1 NAT or Dynamic NAT under the policy.

    Those NAT options are more relevant for scenarios where you need to translate a client's source address to a specific public IP or for inbound publishing. For basic web browsing through the proxy, I'd leave the NAT section at its default unless you have a specific requirement to use a different public IP.

    https://www.watchguard.com/help/docs/help-center/en-US/sports games online/Content/en-US/Fireware/nat/nat_loopback_c.html