11.8.2 Configuring Basic Distributed NAT Functions
To implement dual-system backup for distributed NAT services, distributed NAT must be
configured to implement conversions between private and public addresses for user traffic.
Context
Basic distributed NAT functions need to be configured on master and backup devices. A local
device is used as an example to configure the following functions:
l
Configure basic NAT functions, including: Create a NAT instance. Bind master and slave
service boards to the NAT instance. Create master and backup public NAT address pools.
NOTE
The master public NAT address pool on the local device must be the same as the backup public NAT
address pool on the remote device. The backup public NAT address pool on the local device must
be the same as the master public NAT address pool on the remote device.
l
Configure a NAT user group, including:
–
Configure two private NAT address pools that correspond to the master and backup
public NAT address pools respectively.
–
Bind the private NAT address pool that corresponds to the master public NAT address
pool to an AAA domain.
–
Bind the NAT instance to a user group in the AAA domain.
l
Configure a NAT traffic distribution policy, including:
–
Define a traffic classification rule, traffic classifier, traffic behavior, and traffic policy.
–
Apply the traffic policy.
l
Configure a NAT conversion policy. You need to configure the system to directly perform
a NAT operation for packets and not to match packets with an ACL rule.
NOTE
For details, refer to the chapters Configuring Basic Functions of NAT and Configuring Distributed NAT
for User Traffic in the
HUAWEI NetEngine80E/40E Router Configuration Guide - IPv6 Transition
11.8.3 Configuring Association Between NAT and BRAS Service
Backup
VRRP is used to determine the master and slave states of BRASs that back up each other. mVRRP
can be associated with NAT instances. When the state of a NAT instance changes, a VRRP
master/slave device switchover is triggered so that association between NAT and BRAS service
backup can be implemented.
Context
Dual-system backup of NAT services supports IPv4-based VRRP only.
Perform the following steps on the devices that back up each other:
Procedure
Step 1
Run:
HUAWEI NetEngine80E/40E Router
Configuration Guide - Reliability
11 Multi-node Backup Configuration
Issue 02 (2014-09-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1187