Foundry AR-Series Router User Guide
NAT Configuration Examples
Dynamic NAT (many to many)
In dynamic
10.1.1.4there will be a set of NAT IP address from 60.1.1.1 to 60.1.1.2. In case of
If a NAT IP address cannot be allocated dynamically at the connection creation time, the packet would be dropped.
Figure 15.6 Dynamic NAT
10.1.1.1
10.1.1.2
10.1.1.3
10.1.1.4
OPAL
INTERNET
The dynamic NAT configuration shown in includes:
•Private network
•Public (NAT) IP address range:
To create NAT pool with type dynamic, specify the IP address and the NAT ending IP address.Then add a policy with the source IP address range, and attach the NAT pool to the policy.
Foundry/configure# firewall corp Foundry/configure/firewall corp# object Foundry/configure/firewall corp/object#
dynamic 60.1.1.1 60.1.1.2 Foundry/configure/firewall corp/object# exit
Foundry/configure/firewall corp# policy 8 out | address 10.1.1.1 |
10.1.1.4 any any |
|
Foundry/configure/firewall corp/policy 8 out# | |
pool addresspoolDyna |
|
Foundry/configure/firewall corp/policy 8 out# | exit 2 |
Foundry/configure# |
|
15 - 58 | © 2004 Foundry Networks, Inc. | June 2004 |