116
NAT entries
NAT session entry
NAT translates the IP address of the first packet in a session and creates a NAT session entry for recording
the mappings. The NAT session entry contains extended NAT information, such as interface and
translation method. Subsequent packets of the session are translated by using this entry.
The session management module maintains the updating and aging of NAT session entries. For
information about session management, see
Security Configuration Guide
.
EIM entry
A NAT device with the PAT Endpoint-Independent Mapping configured creates a NAT session entry, and
then an EIM entry for recording the mapping between an internal address/port and a NAT
address/port.
The EIM entry provides the following benefits:
•
The same mapping applies to subsequent connections originating from the same source IP and port
as the first connection.
•
Allows reverse translation for connections originating from external hosts to the NAT address and
port based on the EIM entry.
An EIM entry ages out after all related NAT session entries age out.
NO-PAT entry
A NAT device with NO-PAT translation method configured creates a NAT session entry, and then creates
a NO-PAT entry for recording the mapping between an internal address and a NAT address. A NO-PAT
entry can also be created during the ALG process for NAT. For information about NAT with ALG, see
"
The NO-PAT entry provides the following benefits:
•
The same mapping applies to subsequent connections originating from the same source IP as the
first connection.
•
The
reversible
keyword allows translating the destination IP address of the first packet of a
connection originating from an external host to the NAT address based on the existing NO-PAT
entry.
A NO-PAT entry ages out after all related NAT session entries age out.
Using NAT with other features
NAT with MPLS VPNs
NAT with MPLS L3VPN allows users from different MPLS VPNs to access external networks and to access
each other.
Содержание MSR 2600 Series
Страница 6: ...We appreciate your comments...
Страница 33: ...18 AC vlan1 quit...
Страница 113: ...98 Figure 41 Creating a record d On the page that appears select IPv6 Host AAAA as the resource record type...
Страница 118: ...103...
Страница 168: ...153 H323 Enabled ICMP ERROR Enabled...
Страница 170: ...155 Task Command Display FIB entries display fib vpn instance vpn instance name ip address mask mask length...