Copyright © 2011, Juniper Networks, Inc.
New Features in Junos OS Release 10.4 for M Series, MX Series, and T Series Routers
[
edit routing-instances routing-instance-name routing-options autonomous-system
]
autonomous-system
[Routing Protocols]
Services Applications
NAT-PT with DNS ALG support (M Series and T Series routers)—You can configure
Domain Name Service (DNS) application-level gateways (ALGs) using NAT with
protocol translation (NAT-PT) for IPv6 to IPv4. The implementation is described in
RFC 2766 and RFC 2694.
When you configure NAT-PT with DNS ALG support, you must configure two NAT rules.
The first NAT rule ensures that the DNS query and response packets are translated
correctly. For this rule to work, you must configure a DNS ALG application and reference
it in the rule. The second rule is required to ensure that NAT sessions are destined to
the address mapped by the DNS ALG.
To configure the correct translation of the DNS query and response packets, include
the
dns-alg-pool dns-alg-pool
services nat rule rule-name term term-name then translated]
To configure the DNS ALG application, include the
statement at the
[edit applications]
services nat rule rule-name term term-name from]
To configure destination translation with the DNS ALG address map, use the
use-dns-map-for-destination-translation
rule-name term term-name then translated]
the DNS query or response processing done by the first rule with the actual data
sessions processed by the second rule.
You can also control the translation of IPv6 and IPv4 DNS queries in the following
ways.
For translation control of IPv6 DNS queries, use the
do-not-translate-AAAA-query-to-A-query
application application-name]
For translation control of IPv4 queries, use the
do-not-translate-A-query-to-AAAA-query
application application-name]
NOTE: The above two statements cannot be configured together. You
can only configure one at a time, but not both.
To check that the flows are established properly, use the
stateful-firewall flows
command.
or
dns-alg-prefix dns-alg-prefix
hierarchy level, then reference it at the
statement at the
hierarchy level. This statement correlates
statement at the
hierarchy level.
statement at the
hierarchy level.
command or the
show services stateful-firewall conversations
statement at the
hierarchy level.
application application-name
[edit
hierarchy level.
[edit services nat rule
[edit applications
[edit applications
show services
[edit
23
Need help?
Do you have a question about the JUNOS OS 10.4 - RELEASE NOTES REV 6 and is the answer not in the manual?
Questions and answers