Rockwell Automation Publication 1783-UM007G-EN-P - February 2017 255
Configure Switch Features Chapter 7
If traffic is routed through a Layer 3 switch or router (Figure 27 and Figure 28),
you define the following:
• A private-to-public translation for each device on the private subnet that
communicates on the public subnet.
(1)
• A gateway translation for the Layer 3 switch or router.
You do not need to configure NAT for all devices on the private subnet.
For example, you can choose to omit some devices from NAT to increase
security, decrease traffic, or conserve public address space. By default,
untranslated packets are dropped at the NAT boundary.
Figure 27 - Layer 3 Example with NAT in Stratix 5700 Switch
(1) Machines that communicate with each other within the same VLAN and subnet across a NAT boundary also require public-to-
private translations.
VLAN 10
Machine 1
Controller 2 to Line Controller
Stratix 5700 with NAT
(NAT Instance 2)
192.168.1.2
Line Controller
10.200.1.3
Stratix 5400 with Layer 3 Firmware
VLAN 10: 10.10.1.1
NAT Gateway: 192.168.1.1
VLAN 200: 10.200.1.1
I/O
192.168.1.11
Drive
192.168.1.12
VLAN 10
VLAN 200
VLAN 200
HMI 10.200.1.2
VLAN 10VLAN 10
Machine 2
Controller 2
192.168.1.10
10.10.1.11
Controller 1 to Line Controller
Stratix 5700 with NAT
(NAT Instance 1)
192.168.1.2
I/O
192.168.1.11
Drive
192.168.1.12
Controller 1
192.168.1.10
10.10.1.10