Configuring A Nat Security Profile - Alcatel-Lucent 7705 Configuration Manual

Aggregation router
Hide thumbs Also See for 7705:
Table of Contents

Advertisement

Configuring a NAT Security Profile

To configure NAT, you must first:
To configure a NAT security profile, you must create the profile ID. Once created, the profile
ID is referenced when you set up a NAT policy.
CLI Syntax:
The following example displays a profile configuration.
Example:
7705 SAR OS Router Configuration Guide
configure a NAT security profile and policy in the config>security context
→ in the config>security>profile context, specify the timeouts for the
tcp/udp/icmp protocols. This step is optional. If you do not configure the profile,
a default profile is assigned.
→ in the config>security>policy context, configure a NAT security
policy, and specify the match criteria and the action to be applied to a packet if a
match is found
then configure a NAT zone and apply the policy ID to the zone
config>security# profile profile-id [create]
description description-string
name profile-name
timeouts
config>security# begin
config>security# session-high-wmark 90
config>security# session-low-wmark 70
config>security# profile 2 create
config>security>profile# name "default"
config>security>profile# description "session timer
check"
config>security>profile# timeouts
config>security>profile>timeouts# icmp-request seconds
59
config>security>profile>timeouts# tcp-time-wait minutes
1
config>security>profile>timeouts# exit
config>security>profile# exit
config>security# commit
icmp-request days hours minutes seconds
tcp-established days hours minutes seconds
tcp-syn days hours minutes seconds
tcp-time-wait days hours minutes seconds
tcp-transitory days hours minutes seconds
udp days hours minutes seconds
udp-dns days hours minutes seconds
udp-initial days hours minutes seconds
Filter Policies
307

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents