476
ExtremeWare 7.7 Command Reference Guide
NAT Commands
Usage Guidelines
Four different modes are used to determine how the outside IP addresses and layer 4 ports are
assigned:
•
Static mapping
•
Dynamic mapping
•
Port mapping
•
Auto-constraining
Static and Dynamic Mapping.
When static mapping is used, each inside IP address uses a single
outside IP address. The layer 4 ports are not changed, and only the IP address is rewritten.
With dynamic mapping, the number of inside hosts can be greater than the number of outside hosts.
The outside IP addresses are allocated on a first-come, first-serve basis to the inside IP addresses. The
layer 4 ports are not changed. When the last session for a specific inside IP address closes, that outside
IP address can be used by other hosts.
The
source
IP address specifies private side IP addresses and the
to
IP address (the NAT address)
specifies the public side IP address. The addition of the
destination
optional keyword after the source
IP address and mask species that the NAT rule to be applied to only packets with a specific destination
IP address.
If the netmask for both the source and NAT addresses is /32, the switch uses static NAT translation. If
the netmasks for the source and NAT addresses are not both /32, the switch uses dynamic NAT
translation.
With static or dynamic translation rules, which do not rely on layer 4 ports, ICMP traffic is translated
and allowed to pass.
Port Mapping.
The addition of a layer 4 protocol name and the
portmap
keyword tells the switch to
use port mapping mode. As each new connection is initiated from the inside, the NAT device picks the
next available source layer 4 port on the first available outside IP address. When all ports on a given IP
address are in use, the NAT device uses ports from the next outside IP address.
Optionally, you may specify the range of layer 4 ports the switch chooses on the translated IP addresses.
The default setting for
min
is 1024. The default setting for
max
is 65535. There is a performance penalty
associated with specifying a specific port range other than the default.
ICMP traffic is not translated in port mapping mode. You must add a dynamic NAT rule for the same
IP address range to allow for ICMP traffic.
Auto-constraining.
The auto-constraining algorithm for port-mapping limits the number of outside
layer 4 ports a single inside host can use simultaneously. The limitation is based on the ratio of inside to
outside IP addresses. The outside IP address and layer 4 port space is evenly distributed to all possible
inside hosts. This guarantees that no single inside host can prevent other traffic from flowing through
the NAT device. Because of the large number of simultaneous requests that can be made from a web
browser, it is not recommended that this mode be used when a large number of inside hosts are being
translated to a small number of outside IP addresses.
ICMP traffic is not translated in auto-constrain mode. You must add a dynamic NAT rule for the same
IP address range to allow for ICMP traffic.
Содержание ExtremeWare 7.7
Страница 60: ...60 ExtremeWare 7 7 Command Reference Guide Contents ...
Страница 72: ...72 ExtremeWare 7 7 Command Reference Guide Command Reference Overview ...
Страница 404: ...404 ExtremeWare 7 7 Command Reference Guide VLAN Commands ...
Страница 472: ...472 ExtremeWare 7 7 Command Reference Guide QoS Commands ...
Страница 491: ...show nat ExtremeWare 7 7 Command Reference Guide 491 Platform Availability This command is available on all platforms ...
Страница 492: ...492 ExtremeWare 7 7 Command Reference Guide NAT Commands ...
Страница 890: ...890 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Страница 1043: ...enable ssh2 ExtremeWare 7 7 Command Reference Guide 1043 Platform Availability This command is available on all platforms ...
Страница 1066: ...1066 ExtremeWare 7 7 Command Reference Guide Security Commands Platform Availability This command is available on all platforms ...
Страница 1076: ...1076 ExtremeWare 7 7 Command Reference Guide Security Commands Platform Availability This command is available on all platforms ...
Страница 1130: ...1130 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Страница 1164: ...1164 ExtremeWare 7 7 Command Reference Guide Configuration and Image Commands ...
Страница 1436: ...1436 ExtremeWare 7 7 Command Reference Guide Wireless Commands ...
Страница 1481: ...show eaps ExtremeWare 7 7 Command Reference Guide 1481 Platform Availability This command is available on all platforms ...
Страница 1484: ...1484 ExtremeWare 7 7 Command Reference Guide EAPS Commands Platform Availability This command is available on all platforms ...
Страница 1490: ...1490 ExtremeWare 7 7 Command Reference Guide EAPS Commands ...
Страница 1538: ...1538 ExtremeWare 7 7 Command Reference Guide ESRP Commands Platform Availability This command is available on all platforms ...
Страница 1576: ...1576 ExtremeWare 7 7 Command Reference Guide ESRP Commands ...
Страница 1614: ...1614 ExtremeWare 7 7 Command Reference Guide STP Commands Platform Availability This command is available on all platforms ...
Страница 1621: ...enable stpd ports ExtremeWare 7 7 Command Reference Guide 1621 Platform Availability This command is available on all platforms ...
Страница 1774: ...1774 ExtremeWare 7 7 Command Reference Guide IP Unicast Commands ...
Страница 1824: ...1824 ExtremeWare 7 7 Command Reference Guide IGP Commands Platform Availability This command is available on all platforms ...
Страница 1884: ...1884 ExtremeWare 7 7 Command Reference Guide IGP Commands Platform Availability This command is available on all platforms ...
Страница 1914: ...1914 ExtremeWare 7 7 Command Reference Guide IGP Commands ...
Страница 2000: ...2000 ExtremeWare 7 7 Command Reference Guide BGP Commands i Series Switches Only ...
Страница 2140: ...2140 ExtremeWare 7 7 Command Reference Guide IPX Commands i Series Platforms Only ...
Страница 2156: ...2156 ExtremeWare 7 7 Command Reference Guide ARM Commands BlackDiamond Switch Only ...
Страница 2168: ...2168 ExtremeWare 7 7 Command Reference Guide Remote Connect Commands ...
Страница 2180: ...2180 ExtremeWare 7 7 Command Reference Guide ATM Commands BlackDiamond 6800 Series Platforms Only ...
Страница 2236: ...2236 ExtremeWare 7 7 Command Reference Guide T1 E1 and T3 WAN Commands Alpine 3800 Series Platforms ...
Страница 2346: ...2346 ExtremeWare 7 7 Command Reference Guide PoS Commands BlackDiamond Switch Only ...
Страница 2410: ...2410 ExtremeWare 7 7 Command Reference Guide Power Over Ethernet Commands Summit 300 and 400 24p Switches and Alpine PoE Module ...
Страница 2446: ...2446 ExtremeWare 7 7 Command Reference Guide LLDP Commands ...
Страница 2496: ...2496 ExtremeWare 7 7 Command Reference Guide H VPLS Commands BlackDiamond Switch Only ...
Страница 2620: ...2620 ExtremeWare 7 7 Command Reference Guide Index of Commands ...