Chapter 13 NAT

Figure 129 LAN Computer Queries a Public DNS Server

DNS
xxx.LAN-SMTP.com = ? 1.1.1.1

LAN

xxx.LAN-SMTP.com = 1.1.1.1

192.168.1.21192.168.1.89

The LAN user’s computer then sends traffic to IP address 1.1.1.1. NAT loopback uses the IP address of the ZyWALL’s LAN interface (192.168.1.1) as the source address of the traffic going from the LAN users to the LAN SMTP server.

Figure 130 LAN to LAN Traffic

 

 

 

NAT

Source 192.168.1.1

Source 192.168.1.89

 

SMTP

 

 

SMTP

 

LAN

192.168.1.21192.168.1.89

The LAN SMTP server replies to the ZyWALL’s LAN IP address and the ZyWALL changes the source address to 1.1.1.1 before sending it to the LAN user. The return traffic’s source matches the original destination address (1.1.1.1). If the SMTP server replied directly to the LAN user without the traffic going through NAT, the source would not match the original destination address which would cause the LAN user’s computer to shut down the session.

226

 

ZyWALL 110/310/1100 Series User’s Guide