Configuring VLANs for NAT
Summit24e3 Switch Installation and User Guide
113
NAT Modes
There are 4 different modes used to determine how the outside IP addresses and Layer 4 ports are
assigned.
•
Static mapping
•
Dynamic mapping
•
Port-mapping
•
Auto-constraining
Static Mapping
When static mapping is used, each inside IP address uses a single outside IP address. The Layer 4 ports
are not changed, only the IP address is rewritten. Because this mode requires a 1-to-1 mapping of
internal to external addresses, it does not make efficient use of the external address space. However, it is
useful when you have a small number of hosts that need to have their IP addresses rewritten without
conflicting with other hosts. Because this mode does not rely on Layer 4 ports, ICMP traffic is translated
and allowed to pass.
Dynamic Mapping
Dynamic mapping is similar to static mapping in that the Layer 4 ports are not rewritten during
translation. Dynamic mapping is different in that the number of inside hosts can be greater than the
number of outside hosts. The outside IP addresses are allocated on a first-come, first-serve basis to the
inside IP addresses. When the last session for a specific inside IP address closes, that outside IP address
can be used by other hosts. Since this mode does not rely on Layer 4 ports, ICMP traffic is translated
and allowed to pass.
Port-mapping
Port-mapping gives you the most efficient use of the external address space. As each new connection is
initiated from the inside, the NAT device picks the next available source Layer 4 port on the first
available outside IP address. When all ports on a given IP address are in use, the NAT device uses ports
off of the next outside IP address. Some systems reserve certain port ranges for specific types of traffic,
so it is possible to map specific source Layer 4 port ranges on the inside to specific outside source
ranges. However, this may cause a small performance penalty. In this case, you would need to make
several rules using the same inside and outside IP addresses, one for each Layer 4 port range. ICMP
traffic is not translated in this mode. You must add a dynamic NAT rule for the same IP address range
to allow for ICMP traffic.
Auto-constraining
The auto-constraining algorithm for port-mapping limits the number of outside Layer 4 ports a single
inside host can use simultaneously. The limitation is based on the ratio of inside to outside IP addresses.
The outside IP address and Layer 4 port space is evenly distributed to all possible inside hosts. This
guarantees that no single inside host can prevent other traffic from flowing through the NAT device.
Because of the large number of simultaneous requests that can be made from a web browser, it is not
recommended that this mode be used when a large number of inside hosts are being translated to a
small number of outside IP addresses. ICMP traffic is not translated in this mode. You must add a
dynamic NAT rule for the same IP address range to allow for ICMP traffic.
Содержание Summit Summit24
Страница 12: ...12 Contents Summit24e3 Switch Installation and User Guide Index Index of Commands ...
Страница 14: ...14 Figures Summit24e3 Switch Installation and User Guide ...
Страница 24: ...24 Summit24e3 Switch Installation and User Guide Summit24e3 Switch Overview ...
Страница 32: ...32 Summit24e3 Switch Installation and User Guide Switch Installation ...
Страница 78: ...78 Summit24e3 Switch Installation and User Guide Configuring Ports on a Switch ...
Страница 118: ...118 Summit24e3 Switch Installation and User Guide Network Address Translation NAT ...
Страница 132: ...132 Summit24e3 Switch Installation and User Guide Ethernet Automatic Protection Switching ...
Страница 146: ...146 Summit24e3 Switch Installation and User Guide Quality of Service QoS ...
Страница 158: ...158 Summit24e3 Switch Installation and User Guide Status Monitoring and Statistics ...
Страница 204: ...204 Summit24e3 Switch Installation and User Guide Interior Gateway Routing Protocols ...
Страница 212: ...212 Summit24e3 Switch Installation and User Guide Safety Information ...
Страница 216: ...216 Summit24e3 Switch Installation and User Guide Supported Standards ...
Страница 238: ...238 Index Summit24e3 Switch Installation and User Guide ...
Страница 244: ...244 Index of Commands Summit24e3 Switch Installation and User Guide ...