NAT_S615
Entry ID: 109744660, V1.1, 08/2017
Siemens AG All rights reserved
Remarks
Address translation using NAT has already been performed before the firewall;
consequently, the firewall must use the translated addresses.
To fully enable VLAN2 for access to the automation devices, change the
firewall rule and the NAT rule for the source as follows: 192.168.1.0/24.
No ARP requests to 172.16.1.x are answered.
As a result, these addresses can only be accessed via routing.
For a single CPU, NAPT could also be used (see chapter 2.2).
NETMAP always translates x addresses to x other addresses, which is also
called 1:1 NAT.
All subnets of the objects participating in NETMAP need to be of the same
size, e.g. all are /24.