Dynamic Translations
Dynamic translations use access list rules, to determine whether to apply NAT to
incoming traffic, and NAT address pools, from which a NAT translation can obtain
IP addresses. You use dynamic translation when you want the NAT router to initiate
and manage address translation and session flows between address realms on
demand.
Order of Operations
This section describes the order of operations for both inside-to-outside and
outside-to-inside translation.
Inside-to-Outside Translation
Inside-to-outside translation occurs in the following order:
1.
Inside (privately addressed) traffic enters the router on an interface marked as
inside
.
2.
A route lookup is performed.
3.
If the next interface is marked as
outside
, the router sends the traffic to the server
module.
4.
The server module performs the appropriate translation.
5.
The router forwards the packet to the appropriate egress line module.
6.
The line module sends the packet as outbound traffic using a globally unique
source address (inside source translation), destination address (outside source
translation), and ports (NAPT).
Outside-to-Inside Translation
Outside-to-inside translation occurs in the following order:
1.
Traffic from the outside, public domain enters the router.
2.
All traffic from an interface that is marked
outside
, whether or not it requires
NAT, is sent to the server module.
3.
The server module searches for an associated NAT match.
4.
If the server module:
■
Finds a NAT match, and the destination interface is marked as
inside
, the
server module performs the appropriate translation and sends the packet
to the appropriate destination.
■
Does not find a NAT match, and the destination interface is marked as
inside
,
the server module drops the packet.
■
Does not find a NAT match, and the destination interface is not marked as
inside
, the server module processes the packet normally for its destination.
Order of Operations
■
69
Chapter 2: Configuring NAT
Summary of Contents for IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Page 6: ...vi...
Page 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Page 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Page 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Page 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Page 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Page 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Page 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Page 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Page 357: ...Part 2 Index Index on page 333 Index 331...
Page 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...