
16-7
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 16 Configuring NAT
NAT Overview
Figure 16-6
Remote Host Attempts to Connect to the Real Address
Figure 16-7
shows a remote host attempting to initiate a connection to a mapped address. This address
is not currently in the translation table, so the FWSM drops the packet.
Figure 16-7
Remote Host Attempts to Initiate a Connection to a Mapped Address
Note
For the duration of the translation, a remote host can initiate a connection to the translated host if an
access list allows it. Because the address is unpredictable, a connection to the host is unlikely. However
in this case, you can rely on the security of the access list.
Web Server
www.example.com
Outside
Inside
209.165.201.2
10.1.2.1
10.1.2.27
Translation
209.165.201.10
10.1.2.27
10.1.2.27
132950
FWSM
Web Server
www.example.com
Outside
Inside
209.165.201.2
10.1.2.1
10.1.2.27
209.165.201.10
132951
FWSM
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......