P-793H v 2 Support Notes
9. How do I configure P-793H v2 with NAT for internal servers?
Generally, without IPSec, to configure an internal server for outside access, we
need to configure the server private IP and its service port in SUA/NAT Server
Table.
However, if both NAT and IPSec is enabled in P-793H v2, the edit of the table
is necessary only if the connection is a non-secure connections. For secure
connections, none SUA server settings are required since private IP is
reachable in the VPN case.
For example:
host----P-793H v2(NAT)----DSL Modem----Internet----Secure host
\
\
Non-secure host
10. I am planning my P-793H v2 behind a NAT router. What do I need
to know?
Some tips for this:
The NAT router must support to pass through IPSec protocol. Only ESP tunnel
mode is possible to work in NAT case. In the NAT router is P-793H v2 NAT
router supporting IPSec pass through, default port and the P-793H v2 WAN IP
must be configured in SUA/NAT Server Table.
1.
WAN IP of the NAT router is the tunneling endpoint for this case, not the
WAN IP of P-793H v2.
2. If firewall is turned on in P-793H v2, you must forward IKE port in
Internet interface.
3. If NAT are also enabled in P-793H v2, NAT server is
required for non-secure connections, NAT server is not
required for secure connections and the physical private IP is
used.
For example:
host----P-793H v2----NAT Router----Internet----Secure host
\
35
All contents copy right © 2010 Zy XEL Communications Corporation.