SmartWare Software Configuration Guide
NAPT Traversal
Protocols that do not build on UDP or TCP but directly on IP (e.g. GRE, ESP) and protocols that open addi-
tional connections unknown to the NAT/NAPT component (e.g. FTP, H.323, SIP) do not easily traverse a
NAPT.
The SmartWare NAPT can handle one GRE (Generic Routing Encapsulation) connection and one ESP
(Encapsulating Security Payload) connection at a time. It also routes ICMP messages back to the source of the
concerned connection or to the source of an ICMP Ping message.
To enable NAPT traversal of protocols that open additional connections, the NAPT component must analyze
these protocols at the Application Level in order to understand which NAPT entries for additional connections
it should create and which IP addresses/ports it must modify (e.g. for voice connections in addition to signal-
ing connections). It performs this task for the protocol FTP. Other protocols such as H.323 and SIP cannot
traverse the SmartWare NAPT.
NAT/NAPT configuration task list
To configure the NAT/NAPT component, perform the tasks in the following sections:
•
Creating a NAPT profile (see
•
Activating NAT/NAPT (see
•
Displaying NAT/NAPT configuration information (see
Creating a NAPT profile
A NAPT profile defines the behavior of the NAT/NAPT component, comprising all four types of NAT/
NAPT. (This profile is called 'NAPT profile' and not 'NAT/NAPT profile for historical reasons.) Several
NAPT profiles are admissible but there is only one NAT/NAPT component.
Procedure: To create a NAPT profile and to configure the required types of NAT/NAPT
Mode: Configure
Step 1
node (cfg)#profile napt name
Step 2
node (pf-napt)[ name ]#range local-
ip-range-start local-ip-range-stop
(optional)
global-ip
NAT/NAPT configuration task list
page
123)
page
123)
Command
page
125)
Purpose
Creates the NAPT profile name and activates the
basic behavior of the Dynamic NAPT
Configures and activates the enhanced behavior of
the Dynamic NAPT: local-ip-range-start and local-ip-
range-stop define the subset of local hosts that use
the global NAT address global-ip to access to global
network.
(max. 20 entries)
The IP ranges of different Dynamic NAPT entries must
not overlap each other.
11 • NAT/NAPT configuration
123
Need help?
Do you have a question about the SmartNode Series and is the answer not in the manual?