|
Navigate to the Stateful firewall level
in the configuration hierarchy.
|
- In the J-Web interface, select Configuration>View
and Edit>Edit Configuration.
- Next to Services, click Configure or Edit.
- Next to Stateful firewall, click Configure or Edit.
|
From the [edit] hierarchy level, enter
edit services stateful-firewall.
|
|
Define to-wan-rule and set its match direction.
|
- Next to Rule, click Add new
entry.
- In the Rule name box, type to-wan-rule.
- From the Match direction list, select output.
|
Set the rule name, match direction, term name, and match condition:
set rule to-wan-rule match-direction output term app-term
from application-sets junos-algs-outbound
|
|
Define app-term for the to-wan-rule rule.
|
- Next to Term, click Add new
entry.
- In the Term name box, type app-term.
|
|
Define the match condition for app-term—the default junos-algs-outbound application set.
|
- Next to From, click Configure.
- Next to Application sets, click Add new entry.
- In the Application set name box, type junos-algs-outbound.
- Click OK twice.
|
|
Define an action for app-term.
|
- On the Term app-term page, next to
Then, click Configure.
- In the Designation list, select Accept.
- Click OK twice.
|
Set the action:
set rule to-wan-rule term app-term then accept
|
|
Define accept-all-term for to-wan-rule.
|
- On the Rule to-wan-rule page, next
to Term, click Add new entry.
- In the Term name box, type accept-all-term.
|
Set the term name and the action:
set rule to-wan-rule term accept-all-term then accept
|
|
Define an action for accept-all-term. The action is
taken only if a packet does not match app-term.
|
- Next to Then, click Configure.
- From the Designation list, select Accept.
- Next to Accept, select the check box.
- Click OK three times.
|
|
Define from-wan-rule and set its match direction.
|
- On the Rule page, next to Rule, click Add new entry.
- In the Rule name box, type from-wan-rule.
- From the Match direction list, select input.
|
Set the rule name, match direction, term name, and the match
condition:
set rule from-wan-rule match-direction input term wan-src-addr-term
from source-address 192.168.33.0/24
|
|
Define wan-src-addr-term for the from-wan-rule rule.
|
- Next to Term, click Add new
entry.
- In the Term name box, type wan-src-addr-term.
|
|
Define the match condition for wan-src-addr-term.
|
- Next to From, click Configure.
- Next to Source address, click Add
new entry.
- From the Address list, select Enter
Specific Value—>.
- In the Prefix box, type 192.168.33.0/24.
- Click OK twice.
|
|
Define an action for wan-src-addr-term.
|
- On the Term wan-src-addr-term page,
next to Then, click Configure.
- In the Designation list, select Accept.
- Click OK twice.
|
Set the action:
set rule from-wan-rule term wan-src-addr-term then accept
|
|
Define discard-all-term for from-wan-rule.
|
- On the Rule from-wan-rule page, next
to Term, click Add new entry.
- In the Term name box, type discard-all-term.
|
Set the term name and the action:
set rule from-wan-rule term discard-all-term then discard
|
|
Define an action for discard-all-term. The action is
taken only if a packet does not match wan-src-addr-term.
|
- Next to Then, click Configure.
- From the Designation list, select Discard.
- Click OK three times.
|
|
Navigate to the Nat level in the configuration
hierarchy.
|
- On the main Configuration page next to Services,
click Configure or Edit.
- Next to Nat, click Configure or Edit.
|
From the [edit] hierarchy level, enter
edit services nat
|
|
Define the public-pool address pool name and range.
|
- Next to Pool, click Add new
entry.
- In the Pool name box, type public-pool.
- From the Address choice list, select Address range.
- In the High box, type 10.148.2.32. In
the Low box, 10.148.2.1.
|
Set the address pool name and the range:
set pool public-pool address-range low 10.148.2.1 high 10.148.2.32
|
|
Specify the NAT port pool to be automatically assigned by the router.
|
- Next to Port, click Configure.
- From the Port choice list, select Automatic.
- Click OK twice.
|
Configure the source port translation to be automatic:
set pool public-pool port automatic
|
|
Define nat-to-wan-rule and private-public-term.
|
- On the Nat page, next to Rule, click Add new entry.
- In the Rule name box, type nat-to-wan-rule.
- From the Match direction list, select output.
- Next to Term, select Add new entry.
- In the Term name box, type private-public-term.
- Next to Then, select Configure.
- Next to Translated, select Configure.
- In the Source pool box, type public-pool.
|
Set the rule name, match direction, term name, and the term's
pool name:
set rule nat-to-wan-rule match-direction output term private-public-term
then translated source-pool public-pool
|
|
Set the NAT port translation type for private-public-term.
|
- Next to Translation type, select the check
box.
- Select Configure.
- From the Source list, select dynamic.
- Click OK five times.
|
Set the NAT translation type:
set rule nat-to-wan-rule match-direction output term private-public-term
then translated translation-type source dynamic
|