Network Address Translation Overview
NAT Feature Overview ▀
Cisco ASR 5000 Series Product Overview ▄
OL-22938-02
In case of bypass NAT flow, in most cases the flow gets checkpointed as part of micro checkpoint.
Any information that is checkpointed as part of full checkpoint is always recovered. Data checkpointed through micro
checkpoint cannot be guaranteed to be recovered. The timing of switchover plays a role for recovery of data done
through micro checkpoint. If failover happens after micro checkpoint is completed, then the micro checkpointed data
will get recovered. If failover happens during micro checkpoint, then the data recovered will be the one obtained from
full checkpoint.
Once NAT IP/and Port-Chunks/Bypass NAT flow are recovered, the following holds good:
One-to-one NAT: Since NAT IP address being used for one-to-one NAT is recovered, on-going flows will be
recovered as part of Firewall Flow Recovery algorithm as one-to-one NAT does not change the port.
Many-to-one NAT: On-going flows will not be recovered as the port numbers being used for flows across
chassis peers/SessMgr peers are not preserved.
Bypass NAT Flow: On-going flows will be recovered as part of Firewall Flow Recovery algorithm.
All of the above items is applicable for ICSR as well.
Category
Event
Impacted
Details
One-to-One
NAT
Session
No
Session recovered.
New Traffic
No
NAT will be applied.
Ongoing Traffic
Yes
Cannot differentiate between ongoing traffic and unsolicited traffic. A rule-
match is done and if allowed, NAT will be applied accordingly on the
packet.
Unsolicited Traffic
(downlink packets)
Yes
Cannot differentiate between ongoing traffic and unsolicited traffic.
Translation will be done and packet action taken based on the rule-match.
Many-to-One
NAT
Session
No
Session recovered.
New Traffic
No
NAT will be applied.
Ongoing
Traffic
TCP
Yes
Packet will be dropped.
UDP
Yes and
No
If it is downlink packet, it will be dropped. If it is uplink packet, NAT will be
applied with a new port.
ICMP
Yes and
No
If it is downlink packet, it will be dropped. If it is uplink packet, NAT will be
applied with a new port.
Unsolicited Traffic
(downlink packets)
No
Packet will be dropped.
Bypass NAT
Session
No
Session recovered.
New Traffic
No
Traffic will be NAT bypassed.
Ongoing Traffic
No
Traffic will be NAT bypassed.
Unsolicited Traffic
(downlink packets)
No
Traffic will be NAT bypassed.
For more information, in the
System Enhanced Feature Configuration Guide
, see the
Session Recovery
and
Interchassis
Session Recovery
chapters.
Содержание ASR 5000 Series
Страница 1: ......
Страница 26: ......
Страница 48: ...New In Release 10 0 SCM Features Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 50: ......
Страница 58: ......
Страница 67: ...Product Service and Feature Licenses Default Licenses Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 68: ......
Страница 126: ......
Страница 138: ......
Страница 146: ......
Страница 218: ......
Страница 236: ......
Страница 356: ......
Страница 374: ......
Страница 422: ......
Страница 496: ......
Страница 572: ......
Страница 654: ......
Страница 700: ......
Страница 726: ......
Страница 784: ......
Страница 816: ......
Страница 839: ...Network Address Translation Overview How NAT Works Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 841: ...Network Address Translation Overview How NAT Works Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 844: ......
Страница 906: ......
Страница 926: ......
Страница 942: ......
Страница 943: ...Cisco ASR 5000 Series Product Overview OL 22938 02 Chapter 30 Technical Specifications ...
Страница 966: ......
Страница 967: ...Cisco ASR 5000 Series Product Overview OL 22938 02 Chapter 31 Safety Electrical and Environmental Certifications ...
Страница 972: ......