ZyWALL Series Internet Security Gateway
9-6
NAT Screens
IP addresses to multiple private LAN IP addresses of clients or servers using mapping types. Select either
SUA Only
or
Full Feature
in
WAN IP
.
Selecting
SUA Only
means (latent) multiple WAN-to-LAN and WAN-to-DMZ multiple address translation.
That means that computers on your DMZ with public IP addresses will still have to undergo NAT mapping if
you’re using
SUA Only
NAT mapping. If this is not your intention, then select
Full Feature
NAT and
don’t configure NAT mapping rules to those computers with public IP addresses on the DMZ.
9.3 SUA Server
A SUA server set is a list of inside (behind NAT on the LAN) servers, for example, web or FTP, that you can
make visible to the outside world even though SUA makes your whole inside network appear as a single
computer to the outside world. The DMZ port provides additional safety for connecting your publicly
accessible servers. This makes the LAN more secure by physically separating it from your public servers.
You may enter a single port number or a range of port numbers to be forwarded, and the local IP address of
the desired server. The port number identifies a service; for example, web service is on port 80 and FTP on
port 21. In some cases, such as for unknown services or where one server can support more than one service
(for example both FTP and web service), it might be better to specify a range of port numbers. You can
allocate a server IP address that corresponds to a port or a range of ports.
Many residential broadband ISP accounts do not allow you to run any server processes (such as a Web or
FTP server) from your location. Your ISP may periodically check for servers and may suspend your account
if it discovers any active services at your location. If you are unsure, refer to your ISP.
9.3.1 Default Server IP Address
If you do not assign a
Default Server
IP Address, the ZyWALL discards all packets
received for ports that are not specified here or in the remote management setup.
In addition to the servers for specified services, NAT supports a default server IP address. A default server
receives packets from ports that are not specified in this screen.
9.3.2 Port Forwarding: Services and Port Numbers
The most often used port numbers are shown in the following table. Please refer to RFC 1700 for further
information about port numbers. Please also refer to the Supporting CD for more examples and details on
SUA/NAT.
Table 9-4 Services and Port Numbers
SERVICES PORT
NUMBER
ECHO 7
Содержание Internet Security Gateway ZyWALL 100
Страница 1: ...ZyWALL 10W 30W 50 100 Internet Security Gateway User s Guide Version 3 62 February 2004 ...
Страница 8: ......
Страница 32: ......
Страница 42: ......
Страница 52: ...ZyWALL Series Internet Security Gateway 1 10 Getting to Know Your ZyWALL Figure 1 2 VPN Application ...
Страница 60: ......
Страница 74: ......
Страница 92: ......
Страница 102: ......
Страница 103: ...DMZ and WAN III Part III DMZ and WAN This part covers configuration of the DMZ and WAN screens ...
Страница 104: ......
Страница 108: ......
Страница 124: ...ZyWALL Series Internet Security Gateway 8 16 WAN Screens Figure 8 10 Dial Backup Setup ...
Страница 132: ......
Страница 134: ......
Страница 156: ......
Страница 170: ......
Страница 217: ...VPN IPSec VI Part VI VPN IPSec This part provides information on how to configure Virtual Private Networks ...
Страница 218: ......
Страница 224: ......
Страница 235: ...ZyWALL Series Internet Security Gateway VPN Screens 15 11 Figure 15 5 VPN IKE ...
Страница 260: ......
Страница 262: ......
Страница 282: ...ZyWALL Series Internet Security Gateway 16 20 Certificates Figure 16 9 Trusted CA Details ...
Страница 291: ...ZyWALL Series Internet Security Gateway Certificates 16 29 Figure 16 14 Trusted Remote Host Details ...
Страница 298: ......
Страница 300: ......
Страница 302: ...ZyWALL Series Internet Security Gateway 17 2 Authentication Server Figure 17 1 Local User Database ...
Страница 308: ......
Страница 350: ......
Страница 351: ...Logs IX Part IX Logs This part provides information and instructions for the logs and reports ...
Страница 352: ......
Страница 356: ...ZyWALL Series Internet Security Gateway 20 4 Log Screens Figure 20 2 Log Settings ...
Страница 364: ......
Страница 365: ...Maintenance X Part X Maintenance This part covers the maintenance screens ...
Страница 366: ......
Страница 378: ......
Страница 380: ......
Страница 386: ...ZyWALL Series Internet Security Gateway 22 6 Introducing the SMT Figure 22 5 Advanced Management SMT Menus ...
Страница 406: ......
Страница 420: ......
Страница 428: ......
Страница 446: ......
Страница 466: ......
Страница 490: ......
Страница 504: ......
Страница 524: ......
Страница 536: ......
Страница 538: ......
Страница 554: ......
Страница 574: ......
Страница 580: ......
Страница 586: ......
Страница 588: ......
Страница 590: ......
Страница 592: ......
Страница 604: ......
Страница 608: ......
Страница 610: ......
Страница 614: ......
Страница 624: ......
Страница 634: ......
Страница 636: ......
Страница 648: ......
Страница 654: ......
Страница 680: ......
Страница 682: ......