Defining Dynamic Translations
Dynamic translations use access list rules, to determine whether or not to apply NAT
to incoming traffic, and NAT address pools, from which a NAT translation can allocate
IP addresses. You use dynamic translation when you want the NAT router to initiate
and manage address translation and session flows between address realms on
demand.
To configure dynamic translations:
■
Define any access list rules that the NAT router uses to decide which packets
need translation.
■
Define an address pool from which the NAT router obtains addresses.
■
Define inside and outside source translation rules for the NAT router to create
NAT translations.
■
Mark interfaces as
inside
or
outside
.
■
(Optional) Modify any translation timeout values.
Creating Access List Rules
Before you create a dynamic translation, create the access list rules that you plan to
apply to the translation. For information about configuring access lists, see
“Configuring Routing Policy” on page 3.
The router evaluates multiple commands for the same access list in the order they
were created. An undefined access list implicitly contains a rule to
permit any
. A
defined access list implicitly ends with a rule to
deny any
.
NOTE:
The access lists do not filter any packets; they determine whether the packet
requires translation.
You use the
access-list
command to create an access list.
access-list
■
Use to define an IP access list to permit or deny translation based on the
addresses in the packets.
■
Each access list is a set of permit or deny conditions for routes that are candidates
for translation (that is, moving from the inside network to the outside network).
■
A zero in the wildcard mask means that the route must exactly match the
corresponding bit in the address. A one in the wildcard mask means that the
route does not have to match the corresponding bit in the address.
■
Use the
log
keyword to log an Info event in the ipAccessList log whenever
matching an access list rule.
■
Example
74
■
Defining Dynamic Translations
JUNOSe 11.1.x IP Services Configuration Guide
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...