Full Cone; Restricted Cone - Avaya 1000 Series Configuration Manual

Secure router
Hide thumbs Also See for 1000 Series:
Table of Contents

Advertisement

Since some protocols, like UNIStim are not standardized they can be difficult to interact with.
To deal with this problem the behavior of the NAT device is altered so that it becomes friendly to
new sessions. This change allows these protocols to work through NAT devices with no need
for an Application Level Gateway (ALG), which can be difficult to maintain.
Cone NAT supports any STUN client/server. No new configuration is required specifically. Old
configuration files which defined a NAT translation will now behave in the Cone NAT style. For
related Cone NAT show and debug commands, refer to the Command Reference Guide.

Full Cone

A full cone NAT is one where all requests from the same internal IP address and port are
mapped to the same external IP address and port. Furthermore, any external host can send
a packet to the internal host, by sending a packet to the mapped external address.

Restricted Cone

A restricted cone NAT is one where all requests from the same internal IP address and port
are mapped to the same external IP address and port. Unlike a full cone NAT, an external host
(with IP address X) can send a packet to the internal host only if the internal host had previously
sent a packet to IP address X.
Avaya Secure Router 1000 Series Configuration Guide
Cone NAT
December 2010
117

Advertisement

Table of Contents
loading

Table of Contents