Nat - Apollo VioNet 3000 series User Manual And Instruction Manual

Vionet 3000 series mobile router
Hide thumbs Also See for VioNet 3000 series:
Table of Contents

Advertisement

Option: LIST ALL ACCESS-LIST
Displays all the entries from an Access Control List.
Access Lists>list all access-list 100
Extended Access List 100, assigned to no protocol
ACCESS LIST CACHE. Hits = 0, Miss = 0
Cache size: 32 entries, Promotion zone: 6 entries
ACCESS LIST ENTRIES
1
PERMIT
SRC=172.25.54.33/32
PROT=21
Hits: 0
2
DENY
SRC=0.0.0.0/0
Hits: 0
3
PERMIT
SRC=0.0.0.0/0
PROT=21-44
Hits: 0
Access Lists>
9.3

NAT

9.3.1
Port NAT
This is a very special case of dynamic NAT and currently is the type of NAT most used. Here there are
many local addresses which are translated to the same global address. Now an arbitrary number of
connections are multiplexed using port information (TCP, UDP). The number of simultaneous connections
is limited only by the number of NAT ports available.
The main problem with this type of NAT is that many services only accept connections coming from
privileged ports in order to ensure that it does not come from an ordinary user. To support NAPT, you need
to maintain handlers for each TCP, UDP connection.
To configure port NAT, you need to create a rule within in IP protocol. Configure the following parameters in
this rule:
Local-ip to be used to send the packets through.
Remote-ip, this indicates if this rule is going to be used as an IP, a network, or all.
Indicates that NAPT is going to be executed.
A representation of the parameters that need to be configured is:
protocol ip
rule 1 local-ip <NAT interface address> remote-ip <network address>
rule 1 napt translation
exit
To conduct troubleshooting, enable the NAPT events.
06/13/05 12:12:02
06/13/05 12:12:03
06/13/05 12:12:03
06/13/05 12:12:03
06/13/05 12:12:03
The configuration shown up until now only permits everything to leave with the same source IP address. To
reach an internal machine from the exterior, a port must be opened. An example of the configuration is as
follows:
protocol ip
nat pat
visible-port 80 rule 1 ip 192.168.1.3 port 80
exit
exit
DES=192.34.0.0/16
DES=0.0.0.0/0
DES=0.0.0.0/0
SPORT=34-56
DPORT=2-4
NAPT.004 In (172.25.6.1[1] => 192.168.1.13[512])
NAPT.003 Out (192.168.1.13[512] => 172.25.6.1[1])
NAPT.004 In (172.25.6.1[1] => 192.168.1.13[512])
NAPT.003 Out (192.168.1.13[512] => 172.25.6.1[1])
NAPT.004 In (172.25.6.1[1] => 192.168.1.13[512])
Apollo Video Technology
th
Avenue Southeast – Bothell, WA 98021-8990
24000-35
Toll Free: 888-AVT-USA1; Tel: 425.483.7100; Fax: 425.483.7200
www.apollovideo.com
VioNet 3000 Series Mobile Router | User Guide
Conn:0
Conn:0
Conn:33?
Page 135

Advertisement

Table of Contents
loading

This manual is also suitable for:

Vn-3001Vn-3011aVn-3011bVn-3021c

Table of Contents