Siemens SCALANCE S615 Manual page 7

Nat variants
Hide thumbs Also See for SCALANCE S615:
Table of Contents

Advertisement

2 UseCases at a Glance
If there are additional routers on VLAN2 that must also communicate with VLAN1,
advertise or configure the subnet of VLAN1 there as well.
As a general rule, all subnets must have been advertised to the routers.
Process flow (active connection establishment from CPU to PC)
The IP address 192.168.1.10 cannot be reached locally. The packet is sent to the
gateway.
The SCALANCE S615 has an interface on subnet 192.168.2.0 and forwards the
packet directly to the PC.
From the PC's perspective, the IP address 192.168.2.20 is not local. The reply
packets are also sent to the gateway.
Advantages
Advantages of this scenario:
All nodes can establish connections in any direction.
Each node can be reached through a unique address.
Firewall rules
Bidirectional communication between the two VLANs is enabled in the SCALANCE
S615 firewall.
Figure 2-2
NAT_S615
Entry ID: 109744660,
V1.1,
08/2017
7

Advertisement

Table of Contents
loading

Table of Contents