Huawei S9700 Series Configuration Manual page 99

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
network transmits traffic to the internal host. The NAT device filters the traffic sent to the internal
host.
Easy IP
Easy IP takes the public IP address of the interface as the source address after NAT is performed.
In addition, it uses the Access Control List (ACL) to control the private addresses to be translated.
NAT ALG
Some protocols are sensitive to the NAT function and cannot work correctly without special
processing. Packets of these protocols contain the IP address and/or port number in the payload,
which affects protocol interaction.
The NAT ALG function allows such protocol packets to traverse NAT devices. It replaces the
IP address and port number in the payload to implement transparent transmission and relay of
protocol packets. The NAT ALG of the SPU supports the domain name system (DNS), FTP,
Real-Time Streaming Protocol (RTSP) and Session Initiation Protocol (SIP).
Twice NAT
Basic NAT translates only the source or destination address of packets, whereas twice NAT
translates both the source and destination addresses. The twice NAT technology applies to the
scenario where IP addresses of hosts on private and public networks overlap. As shown in
3-3, the IP address of PC1 on the private network is the same as the IP address of PC3 on the
public network. If PC2 on the private network sends a packet to PC3, the packet will be forwarded
to PC1. Twice NAT translates the overlapping IP address into a unique temporary address (based
on basic NAT) according to the mapping between the overlapping address pool and the
temporary address pool. In this way, packets can be forwarded correctly.
Figure 3-3 Networking of twice NAT
You can configure twice NAT on the SPU as follows:
1.
2.
Issue 01 (2012-03-15)
PC 1
10.0.0.1/24
PC 2
10.0.0.1/24
Configure basic NAT (many-to-many NAT): Configure an NAT address pool that contains
IP addresses 200.0.0.1 to 200.0.0.100 and apply it to the interface connecting to the WAN.
Configure the mapping from overlapping addresses to temporary addresses: 10.0.0.0 to
3.0.0.0.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Switch
DNS Server
3 NAT Configuration
Figure
PC 3
www.web.com
10.0.0.1/24
88

Advertisement

Table of Contents
loading

Table of Contents