Network Tab
Revised 2017-08-31
Firewall
Drawing No. LP0997-C
- 84 -
Sixnet
®
Series SN/RAM
®
6000 & RAM 9000 Software Manual
Click on the
Finish
button. You will be returned to the Masquerade/NAT/DMZ Rules dialog window and the
Masquerade Rules table will now be populated with the recently entered data.
To delete an existing rule, select it in the table and click on the
Delete
button. To edit an existing rule, select it in the
table and click on the
Edit
button.
NAT (Network Address Translation) Rules:
The NAT Rules enables access to the Internet through a single
machine that translates the IP addresses. The NAT itself has one or more IP addresses, but all the machines
behind the NAT have ‘private’ Internet addresses.
One-to-One NAT will perform a complete forwarding of app ports on the Original Destination IP to a new IP address
entered in New Destination. Because the Original Destination need not be configured on this RTU or router, an
interface is not required to setup.
One-to-One NAT Range will perform the same operation as a single One-to-One rule, but over a range of matched
IP Addresses. The pool defined by the Original IP Start
End (the first Original IP will always translate to the first
New IP, the second to the second, etc). The number of entries in each pool must match.
NAT (One-to-One) rule
Click on the
Add
button and the Nat Rules Settings following pop-up window appears:
Label:
Enter a description to describe this NAT Rule. This field is not required for NAT Rules functionality and
it is just for NAT Rule identification. Supported characters are alphanumeric plus the following special
characters: _@-./',;:?~! #$%^&
Original Destination Address (Required):
This field holds the address being transformed by NAT, the IP
seen by a remote host. This address may be owned by an interface on this device or an unowned/fake range
with a corresponding route (static or default). One-to-one NAT will perform a complete forwarding of all ports on
the Original Destination IP to a new IP address entered in New Destination. Both fields can be any valid IP.
Neither need to be already present/configured/owned on a local interface of this device. Ports 1-19 are
excluded.
Note:
Host Redirect and Service Access rules will apply first, and may prevent certain ports from
reaching the New Destination.
New Destination Address (Required):
This field holds the real LAN IP of the destination device behind this
RTU or router. One-to-one NA will perform a complete forwarding of all ports on the Original Destination IP to a
new IP address entered in New Destination. Both fields can be any valid IP. Neither need to be already
present/configured/owned on a local interface of this device. Ports 1-19 are excluded.