(and
untranslates
the destination address when a packet returns before a translation
table entry times out).
The
no
version of this command removes the dynamic translation rule, but does not
remove any previously created translations from the translation table. To remove active
translations from the translation table, see “Clearing Dynamic Translations” on page 76.
ip nat outside source list
•
Use to create dynamic translation rules that specify when to create a translation for
a source address when routing a packet from the outside network to the inside network.
•
Example
host (config) #
ip nat outside source list translation1 pool pool1
•
Use the
no
version to remove the dynamic translation rule; this command does not
remove any dynamic translations from the translation table.
•
See ip nat outside source list.
Defining Translation Timeouts
The router removes unused dynamic translations in the translation table. Use the
ip nat
translation
command to change or disable NAT translation timeouts.
You can set the aging time (in seconds) never) for any of the specified timers:
•
timeout—Dynamic simple translations (not for overloaded translations); default is
86400 seconds (24 hours).
•
dns-timeout—DNS-created protocol translations; default is 120 seconds. These dynamic
translations are installed by the DNS but not yet used; as soon as the translation is
used, the router applies the timeout value mentioned above.
•
udp-timeout—UDP protocol extended translations; default is 300 seconds (5 minutes).
•
tcp-timeout—TCP protocol extended translations; default is 86400 seconds (24
hours).
•
finrst-timeout—TCP connections terminated with reset (RST) or bidirectional finished
(FIN) flags; default is 120 seconds. This timeout applies only to TCP extended
translations. The timer removes unused, closed TCP translations, which allows for
retransmissions.
•
icmp-timeout—ICMP protocol extended translations; default is 300 seconds (5
minutes).
•
gre-timeout—Aging time for GRE protocol translations; default value is 300 seconds
(5 minutes)
All timeouts for this command support a maximum value of 2147483 seconds (about 25
days).
The no version of this command resets the timer to its default value.
ip nat translation
75
Copyright © 2010, Juniper Networks, Inc.
Chapter 2: Configuring NAT
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...