A D D R E S S T R A N S L A T I O N
Configuring Source Network Address Translation
10-2
Security Appliance User Guide
Version 3R2
1 0
C O N F I G U R I N G S O U R C E N E T W O R K A D D R E S S
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
T R A N S L A T I O N
When performing source NAT, the policy translates the source IP address
to a different address. The source IP address is either translated to a
single address or to an address randomly chosen from a pool of
addresses defined in a dynamic IP (DIP) pool.
Figure 10-1
displays an
example of source IP address translation.
Figure 10-1: Source IP Address Translation
Use the
set policy
command with the
nat src
option to specify source
NAT in the policy.
set policy from {zone} to {zone} {src_ad} (dst_ad}
{srvc} nat src permit
If you configure the policy without specifying a DIP pool ID, the policy
uses the source address of the egress interface as the translated address
Use the
set policy
command with the
nat src
and
dip-id
options to
specify the source NAT to use a random address from the DIP pool:
set policy from {zone} to {zone} {src_ad} {dst_ad}
{srvc} nat src dip-id {id} permit
ABOUT PORT ADDRESS TRANSLATION (PAT)
PAT translates the original source port to a random source port to
maintain the uniqueness of all outbound connections. After an outbound
connection is made, the freeGuard Blaze 2100 software enters the
combination of the translated source IP address, translated source port,
and destination IP address in the session table. As more hosts from the
original source network set up connections in the session table, the
entries all have the same translated source IP address, but different
translated source ports.
Содержание freeGuard Blaze 2100
Страница 1: ...freeGuard Blaze 2100 User Guide Version 3R2...
Страница 14: ...I NT R O DU C T I O N About Document Conventions 1 4 Security Appliance User Guide Version 3R2 1...
Страница 24: ...G E T T IN G S T A R T E D Installing the freeGuard Blaze 2100 2 10 Security Appliance User Guide Version 3R2 2...
Страница 82: ...SY ST EM MA N AGEM E N T Using Traceroute 4 22 Security Appliance User Guide Version 3R2 4...
Страница 192: ...P OL IC Y CO NF I G URA T IO N About Schedules 9 28 Security Appliance User Guide Version 3R2 9...
Страница 216: ...P R E DEF I N E D SER V IC ES A 4 Security Appliance User Guide Version 3R2 A...