D-Link DRO-210i manual NAT Exception, Virtual Server/NAPT

Page 33

Network Address Translation

Consider a scenario where WAN1 is used for internet connectivity. NAT must be enabled at WAN1 to enable LAN systems to access the internet. The company’s servers (Web/FTP Server) may be installed at the DMZ interface using public IP Address for direct access from the internet. NAT should not affect the traffic between DMZ and WAN1, because DMZ systems are already using public/global IP Addresses. In this case, NAT can be disabled between DMZ and WAN1.

Say WAN2 Port is used to connect some PCs or IP Phones with global IP Addresses. In this case, NAT is required only for traffic between LAN and WAN1. NAT can be disabled between WAN2 and WAN1 since WAN2 systems already use global IP Addresses.

Select NAT NAT Exception to configure the NAT Exception as explained below.

Web UI

NAT Exception

NAT between

Select Disable to deactivate NAT between WAN1 and WAN2.

WAN1 and WAN2

 

 

 

NAT between

Select Disable to deactivate NAT between WAN1 and DMZ.

WAN1 and DMZ

 

 

 

NAT between

Select Disable to deactivate NAT between WAN2 and DMZ.

WAN2 and DMZ

 

 

 

6.2 Virtual Server

Virtual Servers use NAPT (Network Address and Port Translation) to allow remote users access certain special services on the LAN, such as FTP server for file transfer and STMP or POP3 for e-mail. The administrator configures the Global IP address, TCP or UDP protocol and port number used to access the Server. The router redirects requests from the remote clients to the Internal Server running the specified service on the LAN, by translating the Global IP/Port to the Private IP/Port of the end server.

Select NAT Virtual Server/NAPT to configure the Virtual Server/NAPT as explained below.

Web UI

Virtual Server/NAPT

Interface Name

Select the interface on which the virtual server is to be configured.

Transport Type Select the transport protocol (TCP or UDP) that the application on the virtual server will use for its connections. The transport type is dependent on the application that is providing the service. This is mostly used for non-standard cases where the port numbers are defined by the administrator.

Dlink DRO-210i User Guide

33

Image 33
Contents DRO-210i Table Of Contents Virtual Private Network Bold About This ManualProduct Overview Product OverviewDlink DRO-210i User Guide Hardware Details DRO-210i Package ContentsFront Panel Rear Panel Routing Software FeaturesVPN Tools Optional Port Configuration Port ConfigurationDisabled WAN2/DMZ InterfacesLAN Interface LAN SettingsDMZ Interface Forgot LAN IP ?DMZ Settings WAN InterfaceMaximum Transmission Unit Dynamic Mode Static ModeIP Settings for WAN1 Interface Dhcp Settings for WAN1 InterfaceUnnumbered Interfaces PPPoE ModePPPoE Settings for WAN1 Interface Dhcp DHCP, DNS and TimeDhcp Server DHCP, DNS and TimeDhcp Static Mapping Dhcp Static MappingDhcp Relay Dhcp RelayDNS Proxy DNS Proxy SettingsTime System Time SettingsRouting RoutingStatic Routing Dynamic RoutingStatic Routing RIP Settings Policy Based Routing Routing TableRouting Table Policy Based RoutingTo the same destination Backup Configuration Auto BackupHigh Availability High AvailabilityLoad Balancing Configuration Load BalancingEthernet Link Detection Ethernet WAN Link Detection NAT Interface Configuration NAT Interface ConfigurationNetwork Address Translation NATNAT Configuration NAT ConfigurationNAT Exception Virtual Server NAT ExceptionVirtual Server/NAPT SIP-ALG SIP ALG ConfigurationNAT Session Table NAT TableFirewall Interface Configuration Interface ConfigurationFirewall Firewall PoliciesPolicy Rules Policy RulesInbound Policies Permitted Services Permitted ServicesInbound Policies Inbound PoliciesOutbound Policies IP Permitted RulesAdd Permitted IP Rule Outbound Policies Outbound PoliciesOutbound Policies Service Blocked Rule Blocked ServicesIP Blocked Rules Add Blocked IP RuleUntrusted Domain Domain FilterOutbound Policies Untrusted Domain Trusted DomainJava Filter Web FilterCookie Filter ActiveX FilterKeyword Filter Keyword ExceptionFile Extension Filter Blocking Log MAC FilterAdd Blocked MAC Address Blocking Log TableIntrusion Detection IDS ConfigurationIDS Configuration Black List Intrusion LogIntrusion Log Table Black List TableVirtual Private Network Virtual Private NetworkPeer-To-Peer IPSec Tunnel or PassthroughIPSec Passthrough IPSec TunnelVirtual Private Network Same IKE Encryption algorithm on both ends of a VPN tunnel IPSec Server IPSec Server ConfigurationsMaximum life duration is 86400 seconds Tunnel Remote ID Configuration Tunnel TableLimitation IPSec Status IPSec StatusIPSec Log Table IPSec LogClass Configuration Quality of ServiceQuality of Service HTB QoS ConfigurationsQuality of Service QoS Filter Configurations Filter ConfigurationTOS/DiffServ Type Of Service/DiffServQuality of Service Administration AdministrationDevice Information Device InfoTraffic Statistics Session LogTraffic Statistics SysLog Password ChangeSession Log System LogPassword Recovery Change PasswordSystem SystemUpload/Download Update Firmware/ConfigurationRemote Access Remote AccessPing Test Ping TestAdministration Dlink DRO-210i User Guide Frequently Asked Questions Frequently Asked QuestionsGeneral DHCP, DNS Q6. What is the purpose of Dhcp Server Auto Configuration?High Availability RoutingFirewall Frequently Asked Questions 11.6 NAT 11.7 VPN Q21. What are the call features supported by SIP-ALG?11.8 QoS Frequently Asked Questions