```{admonition} Note This page is still work in progress, and may have errors or missing content. ``` # NAT rules NAT stands for Network Address Translation and is a common way to mask complete networks behind the firewall as if the traffic was coming from the firewall itself. ConiFW currently supports the following NAT types: * Masquerade * SNAT * DNAT NAT rules have some similarities with filtering rules, but they are defined in a separate file. ## Masquerade Masquerade is a type of NAT where the source of traffic is automatically translated to the ip of the outgoing interface. This is best suited to situations where the IP of the outgoing interface is dynamic, e.g. configured via DHCP, like in most residential connections for example. Example: ```yaml --- - comment: Masquerade traffic from lan to net mode: masquerade source: lan dest: net ``` ```{admonition} Note Adding a masquerade statement will only enable NAT, it does not allow traffic to flow through automatically. You need to define a matching policy and/or a filter rule to allow the kind of traffic you want to pass. ``` ## SNAT SNAT is similar to masquerade, but the outgoing IP is defined statically instead of automatically. This is more suited to networks having static IP addresses. Example: ```yaml --- - comment: SNAT traffic from iot to lan mode: snat source: zone: iot ip: 10.43.0.0/24 dest: zone: lan ip: 10.90.0.21 ``` ```{admonition} Note Adding an SNAT statement will only enable NAT, it does not allow traffic to flow through automatically. You need to define a matching policy and/or a filter rule to allow the kind of traffic you want to pass. ``` ## DNAT With DNAT, you can redirect traffic with a specified protocol and port to a host within another zone. This is also known as port forwarding. Example: Redirect incoming tcp traffic to 10.90.0.10:1234 to 10.190.0.20:19129 ```yaml --- - comment: Redirect TCP port 1234 to an IOT device port 19129 mode: dnat source: zone: lan dest: zone: iot ip: 10.190.0.20 proto: tcp original_destination: 10.90.0.10 sourceport: 1234 destport: 19129 log: true ``` ```{admonition} Note Adding a DNAT statement will only enable NAT, it does not allow traffic to flow through automatically. You need to define a matching policy and/or a filter rule to allow the kind of traffic you want to pass. ```