Dynamic Pat - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 5
Configuring Network Address Translation
Network Address Translation Overview

Dynamic PAT

Dynamic PAT, which is also used for Stateful Network Address Translation
(SNAT), translates multiple local source addresses and ports to a single global IP
address and port that are routable on the destination network from a pool of IP
addresses and ports reserved for this purpose. The ACE translates the local
address and local port for multiple connections and/or hosts to a single global
address and a unique port starting with port numbers greater than 1024.
When a local host connects to the destination network on a given source port, the
ACE assigns a global IP address to it and a unique port number. Each host receives
the same IP address but, because the source port number is unique, the ACE sends
the return traffic, which includes the IP address and port number as the
destination, to the correct host.
The ACE supports over 64,000 ports for each unique local IP address. Because the
translation is specific to the local address and local port, each connection, which
generates a new source port, requires a separate translation. For example,
10.1.1.1:1025 requires a separate translation from 10.1.1.1:1026.
The translation is valid only for the duration of the connection, so a user does not
keep the same global IP address and port number. For this reason, users on the
destination network cannot reliably initiate a connection to a host that uses
dynamic PAT (even if the connection is allowed by an ACL). Not only can you not
predict the local or global port number of the host, but the ACE does not create a
translation unless the local host is the initiator. See the
"Configuring Static NAT
and Static Port Redirection"
section for details about reliable access to hosts.
Dynamic PAT allows you to use a single global address, which helps to conserve
routable addresses. Dynamic PAT does not work with some multimedia
applications that have a data stream on a port that is different from the control path
port.
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
5-5
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents