NAT_S615
Entry ID: 109744660, V1.1, 08/2017
Siemens AG All rights reserved
2.9 S7 connection with double NAT
Starting situation
The CPUs are to establish an S7 connection to one another. No gateway is
configured in the modules and no changes are to be made to the hardware
settings.
The S7 connection runs on a port that cannot be changed, TCP 102.
Figure 2-18
VLAN2: 192.168.1.0/24
VLAN1: 192.168.2.0/24
CPU1:
192.168.2.20
Gateway:
None
CPU2:
192.168.1.10
Gateway:
None
192.168.2.1
192.168.1.1
SRC IP:
192.168.1.10
DST IP:
192.168.1.2
SRC IP:
192.168.2.1
DST IP:
192.168.2.20
NAT Table
Additional IP:
192.168.1.2
Requirements
For network separation, the SCALANCE S615 has two VLANs with different
network IDs. As a result, the device has a separate IP address for each VLAN
(in this document: VLAN1: 192.168.2.1 and VLAN2: 192.168.1.1).
In addition, a source and destination NAT table is defined in the SCALANCE S615
to translate the CPU’s message frames to a different IP address. This requires
another IP address from the subnet of VLAN2.