4.
The server module performs the appropriate translation.
5.
The router forwards the packet to the appropriate egress line module.
6.
The line module sends the packet as outbound traffic using a globally unique source
address (inside source translation), destination address (outside source translation),
and ports (NAPT).
Outside-to-Inside Translation
Outside-to-inside translation occurs in the following order:
1.
Traffic from the outside, public domain enters the router.
2.
All traffic from an interface that is marked
outside
, whether or not it requires NAT, is
sent to the server module.
3.
The server module searches for an associated NAT match.
4.
If the server module:
•
Finds a NAT match, and the destination interface is marked as
inside
, the server
module performs the appropriate translation and sends the packet to the
appropriate destination.
•
Does not find a NAT match, and the destination interface is marked as
inside
, the
server module drops the packet.
•
Does not find a NAT match, and the destination interface is not marked as
inside
,
the server module processes the packet normally for its destination.
PPTP and GRE Tunneling Through NAT
You can configure NAT traversal support for GRE flows using simple translations (Basic
NAT). Because PPTP uses an enhanced GRE encapsulation for the PPP payload,
configuring for GRE flows also supports NAT traversal for PPTP tunnels.
NOTE:
Neither port translation (NAPT) nor Firewall traversal for GRE packets is
supported for GRE flows.
When configured, the following types of translations are supported for GRE and PPTP
tunnels:
•
Inside source static simple translations (inbound and outbound)
•
Outside source static simple translations (inbound and outbound)
•
Inside source dynamic simple translations (inbound and outbound)
•
Outside source dynamic simple translations (inbound and outbound)
•
Combinations of the preceding translations (for example, twice NAT)
67
Copyright © 2010, Juniper Networks, Inc.
Chapter 2: Configuring NAT
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...