Nat Features; Nat And Nat Control - H3C S9500 Series Operation Manual

Routing switches
Hide thumbs Also See for S9500 Series:
Table of Contents

Advertisement

Operation Manual – NAT-URPF-VPLS
H3C S9500 Series Routing Switches
encrypted. For example, the encrypted FTP connection cannot be used; otherwise, the
FTP port cannot be translated correctly.

1.2 NAT Features

1.2.1 NAT and NAT Control

According to the NAT procedure illustrated in Figure 1-1, when an internal host tries to
access the external networks, NAT selects a proper public address and substitutes it for
the source address in the packets. In Figure 1-1, the IP address defined on the
outbound interface of the NAT server is selected. In this case, only one internal host
can access external networks at a time. This mode is called one-to-one NAT. When
multiple internal hosts request to access external networks simultaneously, this type of
NAT can only satisfy one of them.
A variation of NAT responds to concurrent requests. It allows a NAT device to be
equipped with multiple public IP addresses. When the first internal host tries to access
external networks, the NAT process selects a public address for it and adds a mapping
record in the NAT table; when the second internal host tries to access external
networks, the NAT process selects another public address, and so on. In this way,
concurrent requests from multiple internal hosts are satisfied. This mode is called
many-to-many NAT.
The features of the two NAT modes are described in the following table:
Table 1-1 NAT modes
Mode
One-to-one
NAT
Many-to-many
NAT
Note:
Since the probability for all internal hosts to request to access external networks is
very low, the number of internal hosts can be much larger than that of public
addresses for the NAT server.
The number of public IP addresses needed depends on the statistical number of
internal hosts that may request to access external networks at traffic peak.
In practice, it is possible that only some specific internal hosts are expected to have
access to the Internet. That is, when the NAT process checks the header of a packet, it
determines whether the included source IP address is in the address range with
The NAT server has only one public IP address.
Only one internal host can access external networks at a time.
The NAT server has multiple public IP addresses.
Concurrent requests from multiple internal hosts can be satisfied.
1-3
Chapter 1 NAT Configuration
Feature

Advertisement

Table of Contents
loading

This manual is also suitable for:

S9505S9508S9512

Table of Contents