APPLICABLE PRODUCTS
Anybus Defender Series 4000 and up
VERSIONS USED IN THIS ARTICLE
- Anybus Defender 2.5.2-2025111723
Anybus Defender – Configure 1:1 NAT Using the Simple NAT Wizard
This guide explains how to configure 1:1 NAT on the Anybus Defender using the Simple NAT Wizard. It covers how to create a mapping between a LAN device and a dedicated WAN-side IP address, how to add additional mappings after the initial setup, and where the resulting configuration can be reviewed under Virtual IPs, 1:1 NAT, and LAN/WAN firewall rules.
Instructions
Anybus Defender – Configure 1:1 NAT Using the Simple NAT Wizard
The Simple NAT Wizard on the Anybus Defender provides a quick way to configure 1:1 Network Address Translation (NAT) between a device on the LAN side and an IP address on the WAN side.
With 1:1 NAT, one LAN device is represented by one dedicated IP address on the WAN network.
Example:
| Device | IP Address |
| Defender WAN | 10.10.10.53/24 |
| Defender LAN | 192.168.200.1/24 |
| LAN Device | 192.168.200.20 |
| NAT / WAN Address | 10.10.10.100 |
In this example, the LAN device at:
192.168.200.20
is represented on the WAN network by:
10.10.10.100
Traffic from the WAN side follows this path:
WAN Device → 10.10.10.100 → Anybus Defender → 1:1 NAT → LAN Device 192.168.200.20
For traffic initiated by the LAN device, the reverse translation is performed:
LAN Device 192.168.200.20 → Anybus Defender → Source translated to 10.10.10.100 → WAN
1. Open the Simple NAT Wizard
Navigate to:
Firewall → NAT → Simple NAT Wizard
Open the Simple NAT Wizard tab.
Click:
Add 1:1 NAT
2. Create the 1:1 NAT Mapping
Using the example network, configure the following:
| Setting | Value |
| Northbound Interface | WAN |
| Southbound Interface | LAN |
| Northbound IP Address | 10.10.10.100 |
| Southbound IP Address | 192.168.200.20 |
| Description | Device_1 |
Northbound Interface
Select:
WAN
The Northbound interface is the external side of the Defender.
This is the network where the translated address will be available.
Southbound Interface
Select:
LAN
The Southbound interface is where the protected device is connected.
If the device is connected through a VLAN instead of the physical LAN interface, select the appropriate VLAN interface.
Northbound IP Address
Enter an unused IP address from the WAN network.
Example:
10.10.10.100
This address represents the LAN device on the WAN network.
Do not use the Defender's own WAN interface address.
In this example:
- Defender WAN: 10.10.10.53
- NAT address: 10.10.10.100
Southbound IP Address
Enter the actual IP address of the device on the LAN side.
Example:
192.168.200.20
This is the real address of the device behind the Defender.
Description
Enter a useful name for the NAT mapping.
Example:
Device_1
Click:
Add 1:1 NAT
If additional devices require 1:1 NAT, repeat the process using a different Northbound IP address for each device.
When finished, click:
Apply
Then
Finish
3. Result
The completed mapping is:
10.10.10.100 ↔ 192.168.200.20
A device on the WAN side communicates with:
10.10.10.100
The Anybus Defender then translates the traffic and forwards it to:
192.168.200.20
Example:
WAN Device 10.10.10.20 ↓ Destination 10.10.10.100 ↓ Anybus Defender ↓ 1:1 NAT ↓ LAN Device 192.168.200.20
The WAN device therefore does not need to communicate directly with the LAN-side IP address.
4. What the Simple NAT Wizard Changes
The Simple NAT Wizard simplifies the configuration process by creating the required NAT-related configuration automatically.
After applying the wizard, the resulting configuration can be inspected in several locations.
The main areas affected are:
- Virtual IPs
- 1:1 NAT Mapping
- LAN Firewall Rules
- WAN Firewall Rules
5. Virtual IP
Navigate to:
Firewall → Virtual IPs
The wizard creates a Virtual IP for the WAN-side NAT address.
In this example:
10.10.10.100
The Virtual IP allows the Defender to handle traffic addressed to the translated WAN address.
The resulting configuration corresponds to:
| Setting | Value |
| Type | IP Alias |
| Interface | WAN |
| Address | 10.10.10.100 |
The Virtual IP represents the LAN device on the WAN network.
The relationship is:
Virtual IP 10.10.10.100 → LAN Device 192.168.200.20
NOTE: Make sure the Virtual IP you choose is not used by other devices to avoid IP address conflict.
6. 1:1 NAT Mapping
Navigate to:
Firewall → NAT → 1:1
The NAT mapping created by the Simple NAT Wizard can be viewed here.
The entry should correspond to:
| Setting | Value |
| Interface | WAN |
| External IP | 10.10.10.100 |
| Internal IP | 192.168.200.20 |
| Description | Generated by SIMPLENAT Wizard: Device_1 |
The mapping is:
External IP
10.10.10.100
↕
Internal IP
192.168.200.20
NOTE: The 1:1 NAT translates not only the destination address, but also the source address for the return traffic. E.g.
Packets on WAN FROM 10.10.10.1 TO 10.10.10.100 will be translated TO 192.168.200.20
Return traffic FROM 192.168.200.20 to 10.10.10.1 will receive FROM IP 10.10.10.100 on the WAN interface.
7. Firewall Rules
NAT and firewall filtering are separate functions.
The NAT configuration translates IP addresses, while the firewall rules determine whether the traffic is permitted.
The Simple NAT Wizard automatically creates firewall rules associated with the 1:1 NAT configuration.
These rules can be inspected under:
Firewall → Rules
LAN Rules
Navigate to:
Firewall → Rules → LAN
Traffic initiated from the LAN side enters the Defender through the LAN interface.
The traffic path is:
LAN Device → LAN Interface → Anybus Defender → WAN
For the example:
192.168.200.20 → Anybus Defender → translated to 10.10.10.100 → WAN
The LAN firewall rule controls whether the LAN device is permitted to send traffic toward the WAN.
NOTE: This allows traffic from this device to ALL destinations. Recommendation is to tighten to only allow what is specifically needed to be reached.
WAN Rules
Navigate to:
Firewall → Rules → WAN
Traffic initiated from the WAN side enters the Defender through the WAN interface.
The traffic path is:
WAN Device → 10.10.10.100 → Anybus Defender → 192.168.200.20
The WAN firewall rule controls whether the WAN-side device is permitted to access the NATted LAN device.
NOTE: This allows all traffic types to the NATed devices. Recommended is to tighten to only allow what services are required, by means of limiting Destination Port and Protocol (UDP / TCP / ICMP). In addition tighten to only allow from specific source IP addresses that are required to reach this NATed device.
© HMS Networks AB 2026