Answered by:
Is Static NAT possible in TMG 2010?

Question
-
Is doing a static NAT possible in TMG 2010 ?
If i'm using an Cisco ASA device i can do a 1:1 NAT from one of our public addresses to one of our internal addresses.
I.E I can redirect request from external ip 209.94.194.42 to internal ip 172.24.0.23
Is this possible in TMG? If so how do i go about doing it?
Tuesday, September 21, 2010 8:26 PM
Answers
-
Are you talking about outbound traffic using a NAT pool then?
Enhanced NAT may be able to help here: http://blogs.technet.com/b/yuridiogenes/archive/2009/09/13/enhancing-nat-with-tmg.aspx
Jason Jones | Forefront MVP | Silversands Ltd | My Blogs: http://blog.msedge.org.uk and http://blog.msfirewall.org.uk
- Marked as answer by Nick Gu - MSFTModerator Friday, October 1, 2010 6:18 AM
Wednesday, September 29, 2010 10:27 PM
All replies
-
You achieve something similar using web and server publishing rules, but this is not quite the same...
TMG has enhanced NAT that allows you to define a specific source address for NAT, but again this is not really "proper" static NAT
Cheers
JJ
Jason Jones | Forefront MVP | Silversands Ltd | My Blogs: http://blog.msedge.org.uk and http://blog.msfirewall.org.uk- Proposed as answer by Nick Gu - MSFTModerator Wednesday, September 22, 2010 9:01 AM
- Marked as answer by Nick Gu - MSFTModerator Saturday, September 25, 2010 5:32 PM
- Unmarked as answer by Dylan Alexander Wednesday, September 29, 2010 6:29 PM
- Unproposed as answer by Dylan Alexander Wednesday, September 29, 2010 6:29 PM
Tuesday, September 21, 2010 9:08 PM -
Hmm, so there is no Static NAT. So there is no way to use my pool of public addresses using TMG, oh well i guess i will have to stick with the Checkpoint UTM (ughh) for now. :(
Wednesday, September 29, 2010 6:29 PM -
Are you talking about outbound traffic using a NAT pool then?
Enhanced NAT may be able to help here: http://blogs.technet.com/b/yuridiogenes/archive/2009/09/13/enhancing-nat-with-tmg.aspx
Jason Jones | Forefront MVP | Silversands Ltd | My Blogs: http://blog.msedge.org.uk and http://blog.msfirewall.org.uk
- Marked as answer by Nick Gu - MSFTModerator Friday, October 1, 2010 6:18 AM
Wednesday, September 29, 2010 10:27 PM -
If what you are asking about is an inbound connection hitting the external TMG IP and going to an inside LAN server, then all you need is to make a server publishing rule.
You can do outbound source IP selection with IPBinder for TCP connections.
Saturday, October 2, 2010 1:16 AM