Nokia M1122, T66280 user manual Icmp FTP

Page 20

single VCC IP address to the public network. The principle of Network Address Port Translation is presented in Figure 15.

Home network (LAN)

 

 

 

Internet (WAN)

src:192.168.1.112:1228

192.168.1.254

 

195.112.12.161

src:195.112.12.161:50001

dst:194.112.11.111:80

NAPT router

dst:194.112.11.111:80

 

 

src:194.112.11.111:80

 

src:194.112.11.111:80

dst:192.168.1.112:1228

 

dst:195.112.12.161:50001

 

 

 

Figure 15 Principle of Network Address Port Translation

NAPT may restrict the operation of some IP applications. NAPT also operates as a simple IP firewall because translation is only allowed when the first packet is transmitted from the LAN. This means that the NAPT table entry is created only when a packet is sent from the home network to the Internet. With server support capability, the user can add static entries to the NAPT table allowing the translation always in both directions. This capability is used to add servers (HTTP, NNTP, and FTP), which are visible to the public IP network via the VCC, on the LAN subnet.

NAPT supports most IP-based protocols. Because NAPT operates on the IP and transport layer, the application that includes IP address and port within the payload will not work properly through NAPT. In many cases, these applications can be passed through the NAPT using Application Layer Gateway functionality (ALG). M1122 has ALG for the following protocols/applications:

DICMP

DFTP

DH.323 including NetMeeting

DCUSeeMe

DPPTP

DIRC

DIPSEC ESP tunnel mode and IKE

Note, that most IPSEC implementations will fail when passed through NAPT. A typical reason is that the identification may fail if the identification is based on IP address. Also, only tunnel mode without Authentication Header (AH) works.

C33906002SE_00

E Copyright Nokia Networks Oy

19

Image 20
Contents Nokia M1122 Introduction to Nokia M1122 Nokia M1122Interfaces Installing M1122Indicator lights M1122 front panel indicators Step-by-step installation procedure Opening a connection Configuring M1122Browser management Main Service Providers pages Service Providers page with PPP configurationService Providers page with Pptp configuration Local Network pages Local portsC33906002SE00 Local Network Dhcp Napt Routing Local Network RoutingStatistics Restart Features Save ConfigData VCC operation LAN interfaceInternal host/gateway interface Network Address Port Translation RoutingBridging Icmp FTP Point-to-Point Tunneling Protocol Pptp Dynamic Host Configuration ProtocolATM and Adsl Choosing the VCC2 for tunneling example Payload encapsulations Weighted Fair Queueing Class of ServicePoint-to-Point Protocol over Ethernet PPPoE Technical specifications AdslBridging Connectors and pin numbering ETH connectorAmbient conditions Ambient conditions, EMC and safetySafety C33906002SE00 C33906002SE00