![Fortinet FortiWAN Скачать руководство пользователя страница 220](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088220.webp)
Optional Services
NAT
Note that for FortiWAN V4.0.x, system does note generate IPv6 default rules for IPv6/IPv4 dual stack
WAN link. It is necessary to add IPv6 default rules manually, or the IPv6 transmission might fail if its
source IP address is a Link-Local address. Please refer to the examples above for this.
Non-NAT
Non-NAT is used for Private Network and MPLS Network where the host in WAN can directly access the host in DMZ,
and where FortiWAN is used to balance VPN load and backup lines.
FortiWAN's inbound and outbound load balancing (Auto Routing and Multihoming) distribute session over multiple
WAN links. It's necessary to make sure the correct NAT rules are applied to every enabled WAN link.
Enable NAT
:
Enable the function, and NAT will translate any private IP to a fixed public IP assigned to a
given WAN link. Disable the function; FortiWAN will act as a general router for the host in
WAN to directly access the host in DMZ.
WAN
:
Enabled WAN links are listed in the menu. Select the WAN link to set and apply NAT rules
to.
NAT Rules
As the previous description, FortiWAN provides typical NAT for out-going session (established from internal host to
external host). Here we describe the NAT rules which specified how to translate source IP address of a out-going
packet into specified IP address of the WAN link. Incoming packets from a external host can be accepted and
forwarded to the correct internal host only if a out-going packet has already be translated and transferred to the same
external host. NAT rules are separated into IPv4 NAT rules and IPv6 NAT rules, which are used to translate a IPv4
address to another IPv4 address and translate a IPv6 address to another IPv6 address respectively. You will see the
default rules at the bottom of the two rule tables, if IPv4 and/or IPv6 addresses are deployed on localhost of the WAN
link.
IPv4 NAT Rules
Customized rules for IPv4-to-IPv4 NAT on a specified WAN link (select from the drop-down menu WAN above).
E
:
Enable the NAT rule or not.
When
:
The predefined time periods during which the rules will apply. Options are Busy, Idle, All-
Times (See "
").
Source
:
The packets sent from the source will be matched. Note: The source IPv4 to be translated
must be the IPv4 address assigned to the LAN or DMZ (See "
").
Destination
:
The packets sent to the destination will be matched (See "
").
Service
:
The packets with the service port number to which users would like NAT to apply. It can be
the TCP/UDP port, or Predefined service groups from [System]->[Service Grouping] (See
"
").
220
FortiWAN Handbook
Fortinet Technologies Inc.
Содержание FortiWAN
Страница 1: ...FortiWAN Handbook VERSION 4 2 1...