Configure dynamic NAT address translation

Source: Internet
Author: User

The H3C router supports the following modes: NAPT, NOPAT, and easy ip. Generally, you can configure the associated ACL and internal global address pool on the interface (you do not need to configure the address pool when using easy ip) to achieve dynamic address translation, allows internal network users to dynamically select available IP addresses in the address pool based on the ACL (optional) policy. However, note: Some H3C devices also support dynamic address translation of interface packets by determining the source address of the outbound interface packets without using the ACL. The difference between NOPAT and NAPT is whether or not to use port information for Dynamic Address Translation: NOPAT is a pure IP address conversion for multiple-to-multiple address translation without using TCP/UDP port information; NAPT is a multi-to-one address translation implemented using TCP/UDP port information. It can be an IP address or port, or a conversion between a port and an IP address at the same time. If you directly use the IP address of the external network interface of the NAT router as the internal Global IP address after the conversion, It is the dynamic NAT address translation mode such as easy ip. In H3C routers, NAT address translation is generally configured on the external network interface (outbound Interface) of the NAT router. However, when an intranet host needs to access the Internet through multiple outbound interfaces, you need to configure the address translation Association on multiple outbound interfaces, and the configuration process is complicated. Therefore, the H3C router provides a configuration scheme for the connection between the internal network interfaces (inbound interfaces. In this way, when the NAT router acts as a tool for mutual access between VPN, when there are many outbound interfaces, you can simplify the configuration by configuring address translation associations on the inbound interfaces that access each private network. The two configuration methods have the following features (currently, they are mainly associated with the outbound Interface): l if you configure the external network interface address association of the NAT router, the first packet sent from an external network interface is first determined by the ACL (or the source address of the packet) to determine whether address translation is allowed, then, find the corresponding address pool (or interface address) based on the Association to convert the source address, and create an address conversion table item. Subsequent data packets are directly converted according to the address conversion table item. L if the network interface address of the NAT router is configured to be associated, packets that meet the specified ACL received from the internal network interface will be first redirected to the NAT service board, then, perform source address translation similar to external network interface address translation. However, this method does not support easy ip address conversion because multiple egress addresses exist. [Note] the support information associated with the network interface address of the NAT router is related to the device model. Please refer to the actual situation of the device. When both the inbound and outbound interface addresses are configured, if the packets match the address translation association rules of both the inbound and outbound interfaces, the outgoing interface rules take precedence, that is, the conversion is performed only according to the outbound interface address conversion Association.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.