ZyXEL P-870H-53A v2 User Guide - Page 72

Full Cone NAT, Symmetric NAT

Page 72 highlights

Chapter 5 WAN Setup encapsulation method assigned influences your choices for IP address and default gateway. Full Cone NAT In full cone NAT, the NAT router maps all outgoing packets from an internal IP address and port to a single IP address and port on the external network. The NAT router also maps packets coming to that external IP address and port to the internal IP address and port. In the following example, the ZyXEL Device maps the source address of all packets sent from the internal IP address 1 and port A to IP address 2 and port B on the external network. The ZyXEL Device also performs NAT on all incoming packets sent to IP address 2 and port B and forwards them to IP address 1, port A. Figure 39 Full Cone NAT Example 1, A 2, B Symmetric NAT The full, restricted and port restricted cone NAT types use the same mapping for an outgoing packet's source address regardless of the destination IP address and port. In symmetric NAT, the mapping of an outgoing packet's source address to a source address in another network is different for each different destination IP address and port. In the following example, the ZyXEL Device maps the source address IP address 1 and port A to IP address 2 and port B on the external network for packets sent to IP address 3 and port C. The ZyXEL Device uses a different mapping (IP address 2 and port M) for packets sent to IP address 4 and port D. A host on the external network (IP address 3 and port C for example) can only send packets to the internal host via the external IP address and port that the NAT router used in sending a packet to the external host's IP address and port. So in 72 P-870H/HW Series User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334

Chapter 5 WAN Setup
P-870H/HW Series User’s Guide
72
encapsulation method assigned influences your choices for IP address and default
gateway.
Full Cone NAT
In full cone NAT, the NAT router maps all outgoing packets from an internal IP
address and port to a single IP address and port on the external network. The NAT
router also maps packets coming to that external IP address and port to the
internal IP address and port.
In the following example, the ZyXEL Device maps the source address of all
packets sent from the internal IP address
1
and port
A
to IP address
2
and port
B
on the external network. The ZyXEL Device also performs NAT on all incoming
packets sent to IP address
2
and port
B
and forwards them to IP address
1
, port
A
.
Figure 39
Full Cone NAT Example
Symmetric NAT
The full, restricted and port restricted cone NAT types use the same mapping for
an outgoing packet’s source address regardless of the destination IP address and
port. In symmetric NAT, the mapping of an outgoing packet’s source address to a
source address in another network is different for each different destination IP
address and port.
In the following example, the ZyXEL Device maps the source address IP address
1
and port
A
to IP address
2
and port
B
on the external network for packets sent to
IP address
3
and port
C
. The ZyXEL Device uses a different mapping (IP address
2
and port
M
) for packets sent to IP address
4
and port
D
.
A host on the external network (IP address
3
and port
C
for example) can only
send packets to the internal host via the external IP address and port that the NAT
router used in sending a packet to the external host’s IP address and port. So in
2, B
1, A