Platform Secure Firewall Management Center Virtual
Activity On-Premises Deployment

NAT Incoming HTTP Traffic to an HTTP Server

If you only have one public IP address, or a very limited number, you can create a network object NAT rule that translates inbound traffic, bound for a static IP address and port, to an internal address. We have provided procedures for specific cases, but you can use them as a model for other supported applications.

Before you begin

Before you begin, create a network object for the http server. For the sake of this procedure, we will call the object, http-object. See for instructions.

Procedure

1

In the left pane, click Security Devices.

2

Click the Devices tab to locate the device or the Templates tab to locate the model device.

3

Click the appropriate device type tab.

4

Select the device you want to create the NAT rule for.

5

Click NAT in the Management pane at the right.

6

Click > Network Object NAT.

7

In section 1, Type, select Static. Click Continue.

8

In section 2, Interfaces, choose inside for the source interface and outside for the destination interface. Click Continue.

9

In section 3, Packets, perform these actions:

  • Expand the Original Address menu, click Choose, and select the http-object.

  • Expand the Translated Address menu, click Choose, and select the Interface.

  • Check Use Port Translation.

  • Select tcp, http, http.

10

Skip section 4, Advanced.

11

For an FDM-managed device, in section 5, Name, give the NAT rule a name.

12

Click Save. The new rule is created in section 2 of the NAT table.

13

Review and deploy now the changes you made, or wait and deploy multiple changes at once.