■
RFC 2993-Architecture Implications of NAT (November 2000)
■
RFC 3022-Traditional IP Network Address Translator (Traditional NAT) (January
2001)
■
RFC 3027-Protocol Complications with the IP Network Address Translator (January
2001)
NAT Configurations
You can configure NAT in several different ways. Each of the following configuration
methods provides a solution for different configuration requirements:
■
Traditional NAT
■
Bidirectional NAT
■
Twice NAT
Traditional NAT
Traditional NAT is the most common method of using address translation. Its primary
use is translating private addresses to legal addresses for use in an external network.
When configured for dynamic operation, hosts within a private network can initiate
access to the external (public) network, but external nodes on the outside network
cannot initiate access to the private network.
Addresses on the private network and public network must not overlap. Also, route
destination advertisements on the public network (for example, the Internet) can
appear within the inside network, but the NAT router does not propagate
advertisements of local routes that reference private addresses out to the public
network.
There are two types of traditional NAT—basic NAT and NAPT.
Basic NAT
Basic NAT provides translation for IP addresses only (called a
simple
translation) and
places the mapping into a NAT table. In other words, for packets outbound from the
private network, the NAT router translates the source IP address and related fields
(for example, IP, TCP, UDP, and ICMP header checksums). For inbound packets, the
NAT router translates the destination IP address (and related checksums) for entries
that it finds in its translation table.
CAUTION:
Although NAT is the simplest translation method, it is the least secure.
By not including port or external host information in the translation, basic NAT allows
access to any port of the private host by any external host.
NAT Configurations
■
65
Chapter 2: Configuring NAT
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...