. . . . .
A D D R E S S T R A N S L A T I O N
Configuring Destination NAT and Port Mapping
Version 3R2
Security Appliance User Guide
10-5
C O N F I G U R I N G D E S T I N A T I O N N A T A N D P O R T
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
M A P P I N G
Destination NAT can translate a single destination address to a single
address (one-to-one), translate one range of destination addresses to a
single address (many-to-one) or translate one range of destination
addresses to another range of addresses (many-to-many) (refer to
Figure 10-3
).
Port mapping increases the number of services supported for a single
address by changing the destination port in one-to-one NAT and many-
to-one NAT configurations. Unlike port address translation, which
randomly assigns the port during translation, port mapping uses a
policy-assigned port.
Figure 10-3: Destination NAT with Port Mapping
Use the
set policy
command with the
nat dst ip
and
port
options to
specify destination NAT and port mapping in the policy:
set policy from {zone} to {zone} {src_addr} (dst_addr}
{srvc} nat dst ip {nat_addr} port {prt_nbr} permit
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
D E S T I N A T I O N N A T C O N F I G U R A T I O N S
This section describes in detail the types of destination NAT
configurations you can use with the appliance. This section includes the
following topics:
•
Configuring Destination NAT: One-to-One
•
Configuring Destination NAT: One-to-One with Port Mapping