configure nat add vlan map
ExtremeWare 7.7 Command Reference Guide
477
Using Layer 4 Port Numbers.
The addition of the
l4-port
optional keyword allows the NAT rule to
be applied to only packets with a specific layer 4 source or destination port. If you use the layer 4-port
command after the source IP/mask, the rule matches only if the port(s) specified are the source layer
4-ports. If you use the
l4-port
command after the destination IP/mask, the rule matches only if the
port(s) specified are the destination layer 4 ports. Both options can be used together to further limit the
rule. If you specify layer 4 ports, ICMP traffic will not be translated and allowed to pass.
Rule Processing.
Rules are processed in order, usually in the order in which they were added. When
a single rule is matched, no other rules are processed. You can view the rule order using the
show nat
rules
command.
Examples
Static Mapping.
The following command defines a static translation rule that specifies that traffic
coming from 192.168.1.12 will be mapped to 216.52.8.32 on the outside VLAN called out_vlan_1:
configure nat add out_vlan_1 map source 192.168.1.12/32 to 216.52.8.32/32
Using /32 as the netmask for both the
source
and
to
netmasks specifies static translation.
Dynamic Mapping.
The following command defines a dynamic translation rule that specifies that
traffic coming from subnet 192.168.1.0 will be mapped to IP addresses in the range of 216.52.8.1 to
216.52.8.31 on outside VLAN
out_vlan_1
:
configure nat add out_vlan_1 map source 192.168.1.0/24 to 216.52.8.1 - 216.52.8.31
Port Mapping.
The following command defines a translation rule that specifies that TCP/UDP packets
coming from 192.168.1.12 and destined for 192.168.5.20 will be mapped to 216.52.8.32 on outside VLAN
out_vlan_1
:
configure nat add out_vlan_1 map source 192.168.1.12/32 destination 192.168.5.20 to
216.52.8.32/32
The following command defines a portmap translation rule that specifies that both TCP and UDP traffic
from subnet 102.168.2.0/25 will be mapped to available layer 4 ports on the IP addresses in the subnet
216.52.8.32/28:
configure nat add out_vlan_2 map source 192.168.2.0/25 to 216.52.8.32 /28 both portmap
The following command defines a portmap translation rule that specifies that only TCP traffic from
subnet 102.168.2.0/25 be mapped to layer 4 ports in the range of 1024-8192 on the IP addresses in the
subnet 216.52.8.64/28:
configure nat add out_vlan_2 map source 192.168.2.128/25 to 216.52.8.64/28 tcp portmap
1024 - 8192
Auto-constraining.
The following command specifies an auto-constrain NAT translation rule that
applies to both TCP and UDP traffic:
configure nat add out_vlan_3 map source 192.168.3.0/24 to 216.52.8.64/32 both
auto-constrain
History
This command was first available in ExtremeWare 6.2.
This command was added to the Summit “
e
” series of switches in ExtremeWare 7.1e.
Содержание ExtremeWare 7.7
Страница 60: ...60 ExtremeWare 7 7 Command Reference Guide Contents ...
Страница 72: ...72 ExtremeWare 7 7 Command Reference Guide Command Reference Overview ...
Страница 404: ...404 ExtremeWare 7 7 Command Reference Guide VLAN Commands ...
Страница 472: ...472 ExtremeWare 7 7 Command Reference Guide QoS Commands ...
Страница 491: ...show nat ExtremeWare 7 7 Command Reference Guide 491 Platform Availability This command is available on all platforms ...
Страница 492: ...492 ExtremeWare 7 7 Command Reference Guide NAT Commands ...
Страница 890: ...890 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Страница 1043: ...enable ssh2 ExtremeWare 7 7 Command Reference Guide 1043 Platform Availability This command is available on all platforms ...
Страница 1066: ...1066 ExtremeWare 7 7 Command Reference Guide Security Commands Platform Availability This command is available on all platforms ...
Страница 1076: ...1076 ExtremeWare 7 7 Command Reference Guide Security Commands Platform Availability This command is available on all platforms ...
Страница 1130: ...1130 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Страница 1164: ...1164 ExtremeWare 7 7 Command Reference Guide Configuration and Image Commands ...
Страница 1436: ...1436 ExtremeWare 7 7 Command Reference Guide Wireless Commands ...
Страница 1481: ...show eaps ExtremeWare 7 7 Command Reference Guide 1481 Platform Availability This command is available on all platforms ...
Страница 1484: ...1484 ExtremeWare 7 7 Command Reference Guide EAPS Commands Platform Availability This command is available on all platforms ...
Страница 1490: ...1490 ExtremeWare 7 7 Command Reference Guide EAPS Commands ...
Страница 1538: ...1538 ExtremeWare 7 7 Command Reference Guide ESRP Commands Platform Availability This command is available on all platforms ...
Страница 1576: ...1576 ExtremeWare 7 7 Command Reference Guide ESRP Commands ...
Страница 1614: ...1614 ExtremeWare 7 7 Command Reference Guide STP Commands Platform Availability This command is available on all platforms ...
Страница 1621: ...enable stpd ports ExtremeWare 7 7 Command Reference Guide 1621 Platform Availability This command is available on all platforms ...
Страница 1774: ...1774 ExtremeWare 7 7 Command Reference Guide IP Unicast Commands ...
Страница 1824: ...1824 ExtremeWare 7 7 Command Reference Guide IGP Commands Platform Availability This command is available on all platforms ...
Страница 1884: ...1884 ExtremeWare 7 7 Command Reference Guide IGP Commands Platform Availability This command is available on all platforms ...
Страница 1914: ...1914 ExtremeWare 7 7 Command Reference Guide IGP Commands ...
Страница 2000: ...2000 ExtremeWare 7 7 Command Reference Guide BGP Commands i Series Switches Only ...
Страница 2140: ...2140 ExtremeWare 7 7 Command Reference Guide IPX Commands i Series Platforms Only ...
Страница 2156: ...2156 ExtremeWare 7 7 Command Reference Guide ARM Commands BlackDiamond Switch Only ...
Страница 2168: ...2168 ExtremeWare 7 7 Command Reference Guide Remote Connect Commands ...
Страница 2180: ...2180 ExtremeWare 7 7 Command Reference Guide ATM Commands BlackDiamond 6800 Series Platforms Only ...
Страница 2236: ...2236 ExtremeWare 7 7 Command Reference Guide T1 E1 and T3 WAN Commands Alpine 3800 Series Platforms ...
Страница 2346: ...2346 ExtremeWare 7 7 Command Reference Guide PoS Commands BlackDiamond Switch Only ...
Страница 2410: ...2410 ExtremeWare 7 7 Command Reference Guide Power Over Ethernet Commands Summit 300 and 400 24p Switches and Alpine PoE Module ...
Страница 2446: ...2446 ExtremeWare 7 7 Command Reference Guide LLDP Commands ...
Страница 2496: ...2496 ExtremeWare 7 7 Command Reference Guide H VPLS Commands BlackDiamond Switch Only ...
Страница 2620: ...2620 ExtremeWare 7 7 Command Reference Guide Index of Commands ...