6
Configuration Example of NAT
In practice, you can configure an internal server through the NAT process so that the internal
server can be accessed by the external network.
Networking Requirements
The company networks with different service are in the EGW2100 security zones with different
security levels. The mappings are described as follows:
l
The WWW server and the FTP server are in the DMZ security zone, and the network
segment is 10.100.20.0/24. Internal employees and external users can access the servers.
l
The external network is in the Untrust security zone.
Requirement: Two internal servers are provide to external users. The internal IP address of the
WWW server is 10.100.20.1/24, and the port is 8080. The internal IP address of the FTP server
is 10.100.20.3/24. For both severs, the external IP address is 202.38.10.2 and the external port
numbers are the default numbers.
Networking Diagram
shows the networking of a NAT configuration example.
Figure 6-1
Networking of a NAT configuration example
PC
WWW Server
10.100.20.1/24
EGW
Ethernet1/0/0
Vlanif5
10.100.20.2/24
Untrust
FTP Server
10.100.20.3/24
DMZ
Ethernet0/0/0
202.38.10.2/24
HUAWEI EGW2100
Web Configuration Guide
6 Configuration Example of NAT
Issue 01 (2010-02-20)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
6-1