1816
C
96: NAT C
HAPTER
Configuring Address
Translation
Introduction to Address
Translation
ONFIGURATION
To do...
Enable NAT
application layer
gateway
Configure NAT log
Configure
connection-limit
n
The support for the nat aging-time command or for the parameters in nat alg
varies with device models.
Address translation is implemented by associating an ACL with an address pool (or
an interface address in case of Easy IP). This association specifies what packets
(defined by ACLs) can use which address (one in the address pool, or the interface
address itself) to access the external network. When an internal host needs to
send data packets to an external network, the NAT gateway checks the first
packet against the ACL to see if it is permitted. If so, NAT chooses an address from
the address pool (or the interface address, depending on the association) to
perform address translation. This address mapping is recorded in an address
translation table so that subsequent packets can be translated directly according
to this mapping entry.
For details about ACL, refer to
The configuration for different forms of address translation varies somewhat:
Easy IP
■
This feature is implemented using the nat outbound acl-number command,
without the address-group keyword specified. When address translation, the
NAT gateway directly uses an interface's public IP address as the translated IP
address, and uses ACLs to restrict the traffic.
One-to-one NAT
■
You need to configure static NAT in system view, and make it effective in interface
view.
Many-to-many NAT
■
You only need to associate an ACL with an address pool, without dealing with
port numbers.
NAPT
■
Use the command...
nat alg { dns | ftp | ils | nbt
| pptp }
Refer to
"Configuring NAT
Log" on page 1818
Refer to
"Configuring
Connection-limit" on page
1820
"Configuring ACLs" on page
Remarks
Optional
Enabled by default
The support for the pptp keyword may
vary by device.
Optional
Disabled by default
Optional
Disabled by default
1881.
Need help?
Do you have a question about the MSR 50 Series and is the answer not in the manual?
Questions and answers