EasyManua.ls Logo

Enterasys Matrix DFE-Gold Series

Enterasys Matrix DFE-Gold Series
944 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuring Network Address Translation (NAT)
18-2 Network Address Translation (NAT) Configuration
NATworkswithDNSbyhavingtheDNSApplicationSpecificGateway(ALG)translatean
addressthatappearsinaDomainNameSystemresponsetoanameorinverselookup.
NATworkswithFTPbyhavingtheFTPALGtranslatetheFTPcontrolpayload.BothFTPPORT
CMDpacketsandPASVpackets,
containingIPaddressinformationwithinthedataportion,are
supported.
TheNATimplementationalsosupportsthetranslationoftheIPaddressembeddedinthedata
portionoffollowingtypesofICMPerrormessage:destinationun reachable(type3),sourcequench
(type4),redirect(type5),timeexceeded(type11)andparameterproblem(type12).
Purpose
TodisplayandsetNATandNAPTconfigurationincludingdynamicpools,staticanddynamic
NATconfigurations,FTPcontrolport,ForceFlows,maximumentriesandtimeoutvalues,and
clearactivetranslations.
NAT Configuration Task List and Commands
Table 181liststhemandatoryandoptionaltasksandcommandsforconfiguringNATonthe
EnterasysMatrixSeriesdevice.Commandsaredescribedintheassociatedsectionsasshown.
Table 18-1 NAT Configuration Task List and Commands
Task Use these commands...
Enable NAT on an inside or outside interface. ip nat {inside | outside}
Define a NAT address pool. ip nat pool name start-ip-address
end-ip-address {netmask netmask |
prefix-length prefix-length}
Enable dynamic translation of inside source addresses. ip nat inside source [list access-list] pool
pool-name [overload | interface vlan vlan-id
[overload]]
Enable static NAT translation of inside source addresses. ip nat inside source static local-ip global-ip
Enable static NAPT translation of inside source
addresses.
ip nat inside source static {tcp | udp} local-ip
local-port global-ip global-port
Specify the NAT FTP control port. ip nat ftp-control-port port-number
Block the defined inside IP addresses from ever
appearing on an outside interface.
ip nat secure-plus
Configure the maximum number of translation entries. ip nat translation max-entries number
Configure NAT translation timeout values. ip nat translation {timeout | udp-timeout |
tcp-timeout | icmp-timeout | dns-timeout |
ftp-timeout} seconds
Display active NAT translations. show ip nat translations [verbose]
Display NAT translation statistics. show ip nat statistics [verbose]
Clear dynamic NAT translations. clear ip nat translation
Clear a specific active simple NAT translation. clear ip nat translation inside global-ip
local-ip
Clear a specific dynamic NAT translation. clear ip nat translation {tcp | upd} inside
global-ip global-port local-ip local-port

Table of Contents

Related product manuals