Internal Server - H3C SecPath F1800-A Operation Manual

H3c secpath f1800-a firewall
Hide thumbs Also See for H3C SecPath F1800-A:
Table of Contents

Advertisement

Operation Manual - Security Defence
H3C SecPath F1800-A Firewall
NAT server can also differentiate them based on their destination addresses and port
numbers and forward them to the internal hosts.
II. Basic Configuration
The NAT on the SecPath F1800-A effectively combines NAPT and many-to-many
NAT together. With NAPT function, the NAT server can multiplex the selected address
in the address pool to reach the upper limit and then select another address for
translation. Compared with many-to-many NAT, it greatly reduces the number of the
public addresses in the address pool.
You can enable or disable NAPT on the SecPath F1800-A by configuring the optional
keyword no-pat.
nat outbound acl-number address-group group-number [ no-pat ]
Associate an ACL and a NAT address pool in interzone view. You can disable NAPT
by selecting the parameter no-pat, that is, only the IP address without the port
number in the data packet is translated. On the contrary, NAPT is enabled. By default,
NAPT is enabled.

3.2.4 Internal Server

I. Overview
NAT can "shield" internal hosts by hiding the architecture of the intranet. However,
sometimes you want to permit some hosts on external networks to access some hosts
on the intranet, such as a WWW server or a FTP server. You can flexibly add servers
on the intranet through NAT. For example, you can use 202.169.10.10 as the external
address of the WWW server and 202.110.10.11 as the external address of the FTP
server. Even you can use 202.110.10.12:8080 as the external address of the WWW
server. Moreover, NAT can provide multiple identical servers such as WWW servers
for external clients.
NAT on the SecPath F1800-A provides some servers on the intranet for some hosts
on external networks. When a client on an external network accesses a server on the
intranet, the NAT device translates the destination address in the request packet into
a private address on the internal server and translates the source address (a private
address) in the response packet into a public address.
6-72
Chapter 3 NAT

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the H3C SecPath F1800-A and is the answer not in the manual?

Subscribe to Our Youtube Channel

Table of Contents