2034
C
HAPTER
133: NAT C
ONFIGURATION
C
OMMANDS
group-number
: Number of a predefined address pool. The value range varies by
device models.
no-pat
: Translates IP addresses only, without dealing with the port information.
Description
Use the
nat outbound
command to enable NAT and associate an ACL with an
address pool. Packets that match the ACL rules will have their internal IP address
replaced by an address from the address pool.
Use the
undo nat outbound
command to remove the association.
Note that:
■
You can configure different associations on one interface. Normally, the
associations are configured on the egress interface of an internal network that
connects to the external network(s).
■
In the case of Easy IP, if you have modified the interface address, you must reset
the original NAT translation table using the
reset nat session
command
before accessing external networks. Otherwise, it is possible that the original
NAT table entries cannot be automatically deleted or deleted with the
reset
nat
command.
■
Once the
undo nat outbound
command is executed, the NAT translation
table entries generated by the
nat outbound
command will not be deleted.
They will be aged out automatically after 5 to 10 minutes. During this period,
users who use these table entries cannot access external networks whereas
other users are not affected. You can also use the
reset nat session
command
to clear all the NAT address translation table entries. However, use of this
command will result in termination of address translation and all users will have
to reestablish connections. Users can make a proper choice as required.
■
When an ACL rule is not operative, no new NAT session entry depending on
the rule can be created. However, an existing connection is still available for
communication.
n
The following restrictions exist for some devices
■
The ACL rules referenced by the same interface cannot conflict. That is, the
source IP address, destination IP address and VPN instance information in any
two ACL rules cannot be the same. For basic ACLs (2,000 to 2,999), if the
source IP address and VPN instance information in any two ACL rules are the
same, a conflict occurs.
■
EASY IP cannot be configured on interface configured with DHCP Client.
■
An address pool must be configured on just one VLAN interface.
Example
# Enable NAT for hosts in the 10.110.10.0/24 segment, using addresses 1.10.10.1
to 1.10.10.20 as the external IP addresses. Assume that interface Serial 1/0 is
connected to the external network.
<Sysname> system-view
[Sysname] acl number 2001
[Sysname-acl-basic-2001] rule permit source 10.110.10.0 0.0.0.255
[Sysname-acl-basic-2001] rule deny
[Sysname-acl-basic-2001] quit
Summary of Contents for MSR 20-20
Page 110: ......
Page 130: ...130 CHAPTER 4 ATM OC 3C STM 1 INTERFACE CONFIGURATION COMMANDS...
Page 141: ...141 Sysname system view Sysname interface atm 5 0 Sysname Atm5 0 shdsl wire 4 auto enhanced...
Page 142: ...142 CHAPTER 5 G SHDSL INTERFACE CONFIGURATION COMMANDS...
Page 150: ...150 CHAPTER 6 ADSL INTERFACE CONFIGURATION COMMANDS...
Page 174: ...174 CHAPTER 8 GENERAL ETHERNET INTERFACE CONFIGURATION COMMANDS...
Page 186: ...186 CHAPTER 9 CONFIGURATION COMMANDS FOR ETHERNET INTERFACES IN BRIDGE MODE...
Page 288: ...288 CHAPTER 17 FUNDAMENTAL CT3 INTERFACE CONFIGURATION COMMANDS...
Page 290: ...290 CHAPTER 18 ISDN BRI INTERFACE CONFIGURATION COMMANDS...
Page 336: ...336 CHAPTER 20 DCC CONFIGURATION COMMANDS...
Page 418: ...418 CHAPTER 24 GVRP CONFIGURATION COMMANDS...
Page 502: ...502 CHAPTER 30 PORT MIRRORING CONFIGURATION COMMANDS...
Page 532: ...532 CHAPTER 32 PPP LINK EFFICIENCY MECHANISM CONFIGURATION COMMANDS...
Page 538: ...538 CHAPTER 33 PPPOE SERVER CONFIGURATION COMMANDS...
Page 548: ...548 CHAPTER 35 PPP DEBUGGING COMMANDS...
Page 596: ...596 CHAPTER 37 ISDN CONFIGURATION COMMANDS...
Page 630: ...630 CHAPTER 38 MSTP CONFIGURATION COMMANDS...
Page 638: ...638 CHAPTER 39 VLAN CONFIGURATION COMMANDS...
Page 652: ...652 CHAPTER 41 VOICE VLAN CONFIGURATION COMMANDS...
Page 670: ...670 CHAPTER 44 LOGICAL INTERFACE CONFIGURATION COMMANDS...
Page 688: ...688 CHAPTER 45 CPOS INTERFACE CONFIGURATION COMMANDS...
Page 696: ...696 CHAPTER 46 ARP CONFIGURATION COMMANDS...
Page 728: ...728 CHAPTER 51 DHCP SERVER CONFIGURATION COMMANDS...
Page 742: ...742 CHAPTER 52 DHCP RELAY AGENT CONFIGURATION COMMANDS...
Page 746: ...746 CHAPTER 53 DHCP CLIENT CONFIGURATION COMMANDS...
Page 750: ...750 CHAPTER 54 DHCP SNOOPING CONFIGURATION COMMANDS...
Page 772: ...772 CHAPTER 57 DNS CONFIGURATION COMMANDS...
Page 786: ...786 CHAPTER 59 IP ADDRESSING CONFIGURATION COMMANDS...
Page 806: ...806 CHAPTER 60 IP PERFORMANCE CONFIGURATION COMMANDS...
Page 818: ...818 CHAPTER 61 IP UNICAST POLICY ROUTING CONFIGURATION COMMANDS...
Page 822: ...822 CHAPTER 62 UDP HELPER CONFIGURATION COMMANDS...
Page 824: ...824 CHAPTER 63 URPF CONFIGURATION COMMANDS...
Page 828: ...828 CHAPTER 64 FAST FORWARDING COMMANDS...
Page 880: ...880 CHAPTER 67 DUAL STACK CONFIGURATION COMMANDS...
Page 888: ...888 CHAPTER 68 TUNNELING CONFIGURATION COMMANDS...
Page 928: ...928 CHAPTER 70 TERMINAL ACCESS CONFIGURATION COMMANDS...
Page 1014: ...1014 CHAPTER 72 BGP CONFIGURATION COMMANDS...
Page 1088: ...1088 CHAPTER 74 IS IS CONFIGURATION COMMANDS...
Page 1106: ...1106 CHAPTER 75 IS IS DEBUGGING COMMANDS...
Page 1212: ...1212 CHAPTER 79 IPV4 ROUTING POLICY CONFIGURATION COMMANDS...
Page 1268: ...1268 CHAPTER 82 IPV6 BGP CONFIGURATION COMMANDS...
Page 1324: ...1324 CHAPTER 85 IPV6 RIPNG CONFIGURATION COMMANDS...
Page 1364: ...1364 CHAPTER 88 IGMP CONFIGURATION COMMANDS...
Page 1430: ...1430 CHAPTER 90 PIM CONFIGURATION COMMANDS...
Page 1504: ...1504 CHAPTER 93 IPV6 PIM CONFIGURATION COMMANDS...
Page 1644: ...1644 CHAPTER 96 MPLS TE CONFIGURATION COMMANDS...
Page 1670: ...1670 CHAPTER 97 MPLS L2VPN CONFIGURATION COMMANDS...
Page 1742: ...1742 CHAPTER 101 IPSEC PROFILE CONFIGURATION COMMANDS...
Page 1774: ...1774 CHAPTER 105 TRAFFIC POLICING TP CONFIGURATION COMMANDS...
Page 1778: ...1778 CHAPTER 106 TRAFFIC SHAPING CONFIGURATION COMMANDS...
Page 1782: ...1782 CHAPTER 107 LINE RATE CONFIGURATION COMMANDS...
Page 1807: ...1807 Sysname system view Sysname qos policy user1 Sysname qospolicy user1...
Page 1808: ...1808 CHAPTER 110 DEFINING POLICY COMMANDS...
Page 1810: ...1810 CHAPTER 111 FIFO QUEUING CONFIGURATION COMMANDS...
Page 1836: ...1836 CHAPTER 116 RTP PRIORITY QUEUE CONFIGURATION COMMANDS...
Page 1838: ...1838 CHAPTER 117 QOS TOKEN CONFIGURATION COMMANDS...
Page 1842: ...1842 CHAPTER 118 PRIORITY MAPPING TABLE CONFIGURATION COMMANDS...
Page 1844: ...1844 CHAPTER 119 PORT PRIORITY CONFIGURATION COMMANDS...
Page 1852: ...1852 CHAPTER 121 WRED CONFIGURATION COMMANDS...
Page 1860: ...1860 CHAPTER 123 MPLS QOS CONFIGURATION COMMANDS...
Page 1874: ...1874 CHAPTER 124 DAR CONFIGURATION COMMANDS...
Page 1947: ...1947 Sysname system view Sysname local user user1 Sysname luser user1 work directory cf...
Page 1948: ...1948 CHAPTER 127 AAA CONFIGURATION COMMANDS...
Page 1990: ...1990 CHAPTER 129 HWTACACS CONFIGURATION COMMANDS...
Page 2008: ...2008 CHAPTER 131 ASPF CONFIGURATION COMMANDS...
Page 2080: ...2080 CHAPTER 135 PORTAL CONFIGURATION COMMANDS...
Page 2086: ...2086 CHAPTER 137 COMMON CONFIGURATION COMMANDS...
Page 2102: ...2102 CHAPTER 138 IPV4 ACL CONFIGURATION COMMANDS...
Page 2118: ...2118 CHAPTER 139 IPV6 ACL CONFIGURATION COMMANDS...
Page 2200: ...2200 CHAPTER 142 SSH2 0 CONFIGURATION COMMANDS...
Page 2314: ...2314 CHAPTER 152 NTP CONFIGURATION COMMANDS...
Page 2328: ...2328 CHAPTER 153 RMON CONFIGURATION COMMANDS...
Page 2350: ...2350 CHAPTER 154 SNMP CONFIGURATION COMMANDS...
Page 2368: ...2368 CHAPTER 156 CONFIGURATION FILE MANAGEMENT COMMANDS...
Page 2390: ...2390 CHAPTER 158 FTP CLIENT CONFIGURATION COMMANDS...
Page 2396: ...2396 CHAPTER 159 TFTP CLIENT CONFIGURATION COMMANDS...
Page 2484: ...2484 CHAPTER 165 MAC ADDRESS TABLE MANAGEMENT CONFIGURATION COMMANDS...
Page 2646: ...2646 CHAPTER 174 DIAL PLAN CONFIGURATION COMMANDS...
Page 2710: ...2710 CHAPTER 178 SIP CONFIGURATION COMMANDS...
Page 2720: ...2720 CHAPTER 179 VOFR CONFIGURATION COMMANDS...