EasyManuals Logo

Enterasys Matrix DFE-Gold Series User Manual

Enterasys Matrix DFE-Gold Series
944 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #623 background imageLoading...
Page #623 background image
Enterasys Matrix DFE-Gold Series Configuration Guide 18-1
18
Network Address Translation (NAT) Configuration
ThischapterdescribestheNetworkAddressTranslation(NAT)configurationsetofcommands
andhowtousethem.
Configuring Network Address Translation (NAT)
TheEnterasysNetworkAddressTranslation(NAT)implementationsupportsBasicNATand
NetworkAddressPortTranslation(NAPT).Inaddition,thefollowingfeaturesarealsosupported:
•StaticandDynamicNATPoolBinding
•FTP,DNS,TELNET,SSH,TFTP,HTTP,NTP(NetworkTimeProtocol),andICMP(withfive
differenterrormessages)softwarepathNATtranslation
•Force
Flows(SecurePlus)
BothbasicNATandNAPTarereferredtoastraditionalNATandprovideamechanismtoconnect
arealmwithprivateaddressestoanexternalrealmwithgloballyuniqueregisteredaddresses.
BasicNATisamethodbywhichIPaddressesaremappedfromonegrouptoanother,transparent
totheenduser.NAPTisamethodbywhichmanynetworkaddresses,alongwiththeirassociated
TCP/UDPports,aretranslatedintoasinglenetworkaddressanditsassociatedTCP/UDPports.
ThestaticaddressbindingfeatureisdesignedforboththebasicNATandNAPTimplementations
tosupportstaticandno
expirebinding,betweeninsideandoutsideNATaddresstranslation.It
supportsonetoonebinding,localaddressestoglobaladdresses,andTCP/UDPportnumber
translations.
ThedynamicaddressbindingfeatureisdesignedforboththebasicNATandNAPT
implementationstosupportdynamicbindingbetweenanaddressfromanaccesslist
oflocal
addressestoanaddressfromapoolofglobaladdresses.IPaddressesdefinedfordynamic
bindingarereassignedwhenevertheybecomeavailablefromtheglobaladdresspool.NAPT
allowsportaddresstranslationforeachIPaddressintheglobalpool.Theportsaredynamically
assignedbetweenarangeof
1024to4999.
Itissometimespossibleforahostontheoutsideglobalnetworkthatknowsaninsidelocal
address,tobeabletosendamessagedirectlytotheinsidelocaladdresswithoutNATtranslation.
Theforceflowsfeature,setusingthecommandipnatsecureplusonpage 18
7,isdesignedtoforce
allflowsbetweentheinsidelocalpoolandtheoutsideglobalnetworktobetranslated.
Router: Unless otherwise noted, the commands covered in this chapter can be executed only
when the device is in router mode. For details on how to enable router configuration modes, refer to
Enabling Router Configuration Modes” on page 2-103.
Note: An Enterasys Feature Guide document that contains a complete discussion on NAT
configuration exists at the following Enterasys web site: http://www.enterasys.com/support/
manuals/

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Enterasys Matrix DFE-Gold Series and is the answer not in the manual?

Enterasys Matrix DFE-Gold Series Specifications

General IconGeneral
BrandEnterasys
ModelMatrix DFE-Gold Series
CategorySwitch
LanguageEnglish

Related product manuals