Configuring The Aging Time Of Nat Connections; Configuring Nat Security Logging - H3C S9500 Series Operation Manual

Routing switches
Hide thumbs Also See for S9500 Series:
Table of Contents

Advertisement

Operation Manual – NAT-URPF-VPLS
H3C S9500 Series Routing Switches
Table 1-12 Set/Restore the thresholds for controlling the setup rate of all addresses or
an individual IP address
Set the thresholds for controlling the
setup rate
Restore the default thresholds for
controlling the setup rate
By default, the default threshold for controlling the setup rate is 250 sessions per
second.

1.3.6 Configuring the Aging Time of NAT Connections

Since the NAT process cannot keep connected all the time, it is necessary to configure
an aging time for NAT connections. An NAT mapping entry is removed from the NAT
mapping table if the aging time expires. You can use the nat aging-time command to
set the aging time for NAT mapping entries processed by NP and ALG (Application
Layer Gateway) mapping entries processed by CPU. The following commands set
valid time for NAT connections. Different time in seconds is set for software and a NP.
Perform the following configuration in system view.
Table 1-13 Configure the aging time of NAT connections
Configure the aging time of NAT
connections
Restore
connections
By default, the aging time of NAT entries requiring Application Level Gateway (ALG)
processing is 120 seconds, the aging time of NAT entries requiring FTP processing is
7,200 seconds, the aging time of H.323 and ILS is 600 seconds, the aging time of NP
FAST is 300 seconds and the aging time of SLOW is 660 seconds.

1.3.7 Configuring NAT Security Logging

Security log is used to log the detailed procedure information of the NAT process.
Security log includes the following items:
The source IP addresses and port numbers for translating
The destination IP addresses and port numbers for translating
The translated source IP addresses and port numbers
The start time and end time of the NAT process
Operation
Operation
the
aging
time
of
nat blacklist limit rate { limit-rate }
undo nat blacklist limit rate [ source
{ ip | ip-address } ]
nat aging-time { alg time-value | np
slow }
NAT
undo nat aging-time [ alg time-value |
np slow ]
1-14
Chapter 1 NAT Configuration
Command
Command

Advertisement

Table of Contents
loading

This manual is also suitable for:

S9505S9508S9512

Table of Contents