Enterasys Matrix DFE-Gold Series Configuration Guide 18-1
18

Network Address Translation (NAT) Configuration

ThischapterdescribestheNetworkAddressTranslation(NAT)configurationsetofcommands
andhowtousethem.

Configuring Network Address Translation (NAT)

TheEnterasysNetworkAddressTranslation(NAT)implementationsupportsBasicNATand
NetworkAddressPortTranslation(NAPT).Inaddition,thefollowingfeaturesarealsosupported:
•StaticandDynamicNATPoolBinding
•FTP,DNS,TELNET,SSH,TFTP,HTTP,NTP(NetworkTimeProtocol),andICMP(withfive
differenterrormessages)softwarepathNATtranslation
•ForceFlows(SecurePlus)
BothbasicNATandNAPTarereferredtoastraditionalNATandprovideamechanismtoconnect
arealmwithprivateaddressestoanexternalrealmwithgloballyuniqueregisteredaddresses.
BasicNATisamethodbywhichIPaddressesaremappedfromonegrouptoanother,transparent
totheenduser.NAPTisamethodbywhichmanynetworkaddresses,alongwiththeirassociated
TCP/UDPports,aretranslatedintoasinglenetworkaddressanditsassociatedTCP/UDPports.
ThestaticaddressbindingfeatureisdesignedforboththebasicNATandNAPTimplementations
tosupportstaticandnoexpirebinding,betweeninsideandoutsideNATaddresstranslation.It
supportsonetoonebinding,localaddressestoglobaladdresses,andTCP/UDPportnumber
translations.
ThedynamicaddressbindingfeatureisdesignedforboththebasicNATandNAPT
implementationstosupportdynamicbindingbetweenanaddressfromanaccesslistoflocal
addressestoanaddressfromapoolofglobaladdresses.IPaddressesdefinedfordynamic
bindingarereassignedwhenevertheybecomeavailablefromtheglobaladdresspool.NAPT
allowsportaddresstranslationforeachIPaddressintheglobalpool.Theportsaredynamically
assignedbetweenarangeof1024to4999.
Itissometimespossibleforahostontheoutsideglobalnetworkthatknowsaninsidelocal
address,tobeabletosendamessagedirectlytotheinsidelocaladdresswithoutNATtranslation.
Theforceflowsfeature,setusingthecommandipnatsecureplusonpage 187,isdesignedtoforce
allflowsbetweentheinsidelocalpoolandtheoutsideglobalnetworktobetranslated.
Router: Unless otherwise noted, the commands covered in this chapter can be executed only
when the device is in router mode. For details on how to enable router configuration modes, refer to
Enabling Router Configuration Modes” on page 2-103.
Note: An Enterasys Feature Guide document that contains a complete discussion on NAT
configuration exists at the following Enterasys web site: http://www.enterasys.com/support/
manuals/