User guide
 System Administrator’s Guide – Release 7.5 
_______________________________________________________________________________________________________________ 
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com 
Revised: April 9, 2013 
Page 31 
5.4  Network Mode: NAT/Firewall 
When the network mode is set to NAT/Firewall, the logical network capability is as shown in the 
diagram below: 
For security purposes, this mode’s default settings permit only outbound connections (from the LAN 
to the WAN); all WAN-initiated connections are denied. In addition, all packets are subject to network 
address translation (NAT). Because of this, the addresses of devices on the LAN are not visible on 
the WAN, yet they have access to the WAN for outbound traffic. These features reduce the ability of 
WAN hosts to attack LAN hosts. 
Expose the specific LAN sports to enable WAN access to specific LAN network services through the 
firewall. To configure, go to Network > Configuration > Modify and go to the Firewall section. 
Allworx server
IP Based
Network Router
WAN Side
Server Network Services
LAN Side
Server Network Services
WAN
LAN
NAT Firewall










