P312 Broadband Security Gateway

 

 

 

 

 

 

 

 

 

Field

Description

Option/Example

 

 

 

examples.

and Server

 

 

 

 

Local IP

Only local IP fields are N/A for server;

 

 

 

 

 

 

Global IP fields MUST be set for

 

 

 

 

 

 

Server.

0.0.0.0

 

 

 

 

Start

This is the starting local IP address (ILA).

 

 

 

 

End

This is the ending local IP address (ILA). If

255.255.255.255

 

 

 

 

 

the rule is for all local IPs, then put the Start

 

 

 

 

 

 

IP as 0.0.0.0 and the End IP as

 

 

 

 

 

 

255.255.255.255. This field is N/A for One-

 

 

 

 

 

 

to-One and Server types.

 

 

 

 

 

Global IP

 

0.0.0.0

 

 

 

 

Start

This is the starting global IP address (IGA).

 

 

 

 

 

If you have a dynamic IP, enter 0.0.0.0 as

 

 

 

 

 

 

the Global IP Start. Note that Global IP

 

 

 

 

 

 

Start can be set to 0.0.0.0 only if the types

 

 

 

 

 

 

are Many-to-One or Server.

172.16.23.55

 

 

 

 

End

This is the ending global IP address (IGA).

 

 

 

 

 

This field is N/A for One-to-One, Many-to-

 

 

 

 

 

 

One and Server types.

 

 

 

 

 

 

 

 

 

 

Note: For all Local and Global IPs, the End IP address must begin after the IP Start address, i.e., you cannot have an End IP address beginning before the Start IP address.

6.3NAT Server Sets

A NAT server set is a list of inside servers (behind NAT on the LAN) that you can make visible to the outside world. Menu 15.2 – NAT Server Sets is used to configure these servers. If you’re using Ethernet Encapsulation with either RR-Manageror RR-ToshibaService Type port 12 set to 1025 (non-editable) as displayed in Figure 6-11.

6.3.1 Multiple Servers behind NAT

If you wish, you can make inside servers for different services, e.g., web or FTP, visible to the outside users, even though NAT makes your whole inside network appear as a single machine to the outside world. A service is identified by the port number, e.g., web service is on port 80 and FTP on port 21.

As an example (see the following figure), if you have a web server at 192.168.1.36 and an FTP server 192.168.1.33, then you need to specify for port 80 (web) the server at IP address 192.168.1.36 and for port 21 (FTP) another at IP address 192.168.1.33.

Please note that a server can support more than one service, e.g., a server can provide both FTP and DNS service, while another provides only web service.

NAT

6-11

Page 84
Image 84
ZyXEL Communications P-312 manual NAT Server Sets, Multiple Servers behind NAT