DNAT XG18 missing basic features
With a new server access assistant (DNAT) in SFOS 18.0.0 GA-Build339:
1) You cannot select different original and translated port in a wizard
2) You cannot create service inside the wizard
3) You cannot create external source inside the wizard}
4) The firewall rule shows allowed access to WAN interface instead of a local IP, which is misleading
5) Wizard is automatically created reflexive rule effective destroying original, desired SNAT for the server.
Instead of the 1 original rule in 17.5 you have 3-4 different rules on 2 screens (1 fw and 2-3 NAT rules)... not cool at all!
Obviously I don't count SD-WAN rule on top...

1 comment
-
lferrara commented
https://community.sophos.com/products/xg-firewall/f/firewall-and-policies/118794/v17-vs-v18-things-that-are-just-a-step-backward
I agree. v17 was using a simpler way to creating rules. A separated NAT tab was needed but a better implementation is more than needed.