TOPEX Bytton (HSPA+ / LTE)
ByttonLTE(full)_genericUsermanual_sw306FAS_revN.1.docx
Page: 133 / 290
You can define as many Masquerading rules as you need:
After applying a Commit, you can see the new masquerading rules as active in the automated Firewall of
Bytton LTE:
Firewall view rule
# Generated by iptables-save v1.4.10 on Tue Dec 11 15:01:05 2012
*nat
:PREROUTING ACCEPT [973:87799]
:OUTPUT ACCEPT [226:13596]
:POSTROUTING ACCEPT [168:10080]
-A POSTROUTING -o ppp3 -j MASQUERADE
-A POSTROUTING -o ppp3 -j MASQUERADE
-A POSTROUTING -o wan -j MASQUERADE
-A POSTROUTING -o ppp1 -j MASQUERADE
COMMIT
# Completed on Tue Dec 11 15:01:05 2012
Note
:
Although masquerading may be applied for all interfaces of the Bytton LTE device, it makes sense
only for remote networks, this is why the “NAT” sub-page was places inside the WAN menu.
NAT –what and why?
It performs IP Masquerading or NAT (translation of source and destination IP addresses and port numbers
upon data packets).
Network Address Translation basically allows a single device, such as the Bytton LTE router, to act as
agent between the a public network (such as the Internet) and one or several local (or private) networks.
This means that for the representation of the entire group of local machines to anything outside their
network just a single unique IP address is required!
Besides this “address range compression” feature, NAT is also used for Security and Administration.
Implementation of dynamic NAT automatically creates a firewall between your internal network and
outside networks or the Internet.
Dynamic NAT allows only connections that originate inside the stub domain. Another l benefit of NAT is
simpler network administration. Changes to the internal networks may be performed easily since the only
external IP address either belongs to the router or comes from a pool of global addresses. And in case of
changing the host for various services, it is enough to change the inbound mapping with the new inside
local address at the router to reflect the new host.
When the Internet provider that you connect to performs the masquerading at its location, you do not
need to do NAT anymore, you should leave this option Disabled.
This is why the NAT table of Bytton LTE does allow
selective
masquerading, you can select to enable or
not NAT for each of the interfaces: