Nat Control; Nat Implementations; Static Nat; Dynamic Nat - HPE FlexNetwork HSR6800 Configuration Manual

Comware 7 layer 3, ip services
Hide thumbs Also See for FlexNetwork HSR6800:
Table of Contents

Advertisement

Bidirectional NAT
NAT translates the source and destination IP addresses of incoming packets on the receiving
interface and outgoing packets on the sending interface.
Bidirectional NAT is applied when source and destination addresses overlap.
Twice NAT
Twice NAT translates the destination IP address on the receiving interface, and the source IP
address on the sending interface. The receiving and sending interfaces are both NAT interfaces.
Twice NAT allows VPNs with overlapping addresses to access each other.
NAT hairpin
NAT hairpin allows internal hosts to access each other through NAT. The source and destination IP
address of the packets are translated on the interface connected to the internal network.
NAT hairpin includes P2P and C/S modes:
P2P—Allows internal hosts to access each other through NAT.
C/S—Allows internal hosts to access internal servers through NAT.

NAT control

You can use ACLs to implement NAT control. The match criteria in the ACLs include the source IP
address, source port number, destination IP address, destination port number, transport layer
protocol, and VPN instance. Only packets permitted by an ACL are processed by NAT.

NAT implementations

Static NAT

Static NAT creates a fixed mapping between a private address and a public address. Static NAT
allows bidirectional connection initiation, both from and to the internal host. Static NAT applies to
regular communications.

Dynamic NAT

Dynamic NAT uses an address pool to translate addresses. Dynamic NAT includes Not Port Address
Translation (NO-PAT) and Port Address Translation (PAT) modes.
NO-PAT
NO-PAT translates a private address to a public address. The public address cannot be used by
another internal host until it is released.
NO-PAT supports all IP packets.
PAT
PAT translates multiple private addresses to a single public address by mapping the private address
and source port to the public address and a unique port. PAT supports TCP and UDP packets, and
ICMP request packets.
113

Advertisement

Table of Contents
loading

Table of Contents