ZyXEL UAG715 User Guide - Page 191

NAT Technical Reference

Page 191 highlights

Chapter 14 NAT Table 77 Configuration > Network > NAT > Add (continued) LABEL Original Service Mapped Service Protocol Type Original Port Mapped Port Original Start Port Original End Port Mapped Start Port Mapped End Port Enable NAT Loopback DESCRIPTION This field is available if Port Mapping Type is Service. Select the original service whose destination port(s) is supported by this NAT rule. This field is available if Port Mapping Type is Service. Select the translated service whose destination port(s) is supported if this NAT rule forwards the packet. This field is available if Port Mapping Type is Port or Ports. Select the protocol (TCP, UDP, or any) used by the service requesting the connection. This field is available if Port Mapping Type is Port. Enter the original destination port this NAT rule supports. This field is available if Port Mapping Type is Port. Enter the translated destination port if this NAT rule forwards the packet. This field is available if Port Mapping Type is Ports. Enter the beginning of the range of original destination ports this NAT rule supports. This field is available if Port Mapping Type is Ports. Enter the end of the range of original destination ports this NAT rule supports. This field is available if Port Mapping Type is Ports. Enter the beginning of the range of translated destination ports if this NAT rule forwards the packet. This field is available if Port Mapping Type is Ports. Enter the end of the range of translated destination ports if this NAT rule forwards the packet. The original port range and the mapped port range must be the same size. Enable NAT loopback to allow users connected to any interface (instead of just the specified Incoming Interface) to use the NAT rule's specified Original IP address to access the Mapped IP device. For users connected to the same interface as the Mapped IP device, the UAG uses that interface's IP address as the source address for the traffic it sends from the users to the Mapped IP device. For example, if you configure a NAT rule to forward traffic from the WAN to a LAN server, enabling NAT loopback allows users connected to other interfaces to also access the server. For LAN users, the UAG uses the LAN interface's IP address as the source address for the traffic it sends to the LAN server. See NAT Loopback on page 192 for more details. Firewall If you do not enable NAT loopback, this NAT rule only applies to packets received on the rule's specified incoming interface. By default the firewall blocks incoming connections from external addresses. After you configure your NAT rule settings, click the Firewall link to configure a firewall rule to allow the NAT rule's traffic to come in. OK Cancel The UAG checks NAT rules before it applies To-Device firewall rules, so To-Device firewall rules do not apply to traffic that is forwarded by NAT rules. The UAG still checks other firewall rules according to the source IP address and mapped IP address. Click OK to save your changes back to the UAG. Click Cancel to return to the NAT summary screen without creating the NAT rule (if it is new) or saving any changes (if it already exists). 14.3 NAT Technical Reference Here is more detailed information about NAT on the UAG. UAG715 User's Guide 191

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542

Chapter 14 NAT
UAG715 User’s Guide
191
14.3
NAT Technical Reference
Here is more detailed information about NAT on the UAG.
Original Service
This field is available if
Port Mapping Type
is
Service
. Select the original service whose
destination port(s) is supported by this NAT rule.
Mapped Service
This field is available if
Port Mapping Type
is
Service
. Select the translated service
whose destination port(s) is supported if this NAT rule forwards the packet.
Protocol Type
This field is available if
Port Mapping Type
is
Port
or
Ports
. Select the protocol (
TCP
,
UDP
, or
any
) used by the service requesting the connection.
Original Port
This field is available if
Port Mapping Type
is
Port
. Enter the original destination port
this NAT rule supports.
Mapped Port
This field is available if
Port Mapping Type
is
Port
. Enter the translated destination port
if this NAT rule forwards the packet.
Original Start Port
This field is available if
Port Mapping Type
is
Ports
. Enter the beginning of the range of
original destination ports this NAT rule supports.
Original End Port
This field is available if
Port Mapping Type
is
Ports
. Enter the end of the range of
original destination ports this NAT rule supports.
Mapped Start Port
This field is available if
Port Mapping Type
is
Ports
. Enter the beginning of the range of
translated destination ports if this NAT rule forwards the packet.
Mapped End Port
This field is available if
Port Mapping Type
is
Ports
. Enter the end of the range of
translated destination ports if this NAT rule forwards the packet. The original port range
and the mapped port range must be the same size.
Enable NAT
Loopback
Enable NAT loopback to allow users connected to any interface (instead of just the
specified
Incoming Interface
) to use the NAT rule’s specified
Original IP
address to
access the
Mapped IP
device. For users connected to the same interface as the
Mapped
IP
device, the UAG uses that interface’s IP address as the source address for the traffic it
sends from the users to the
Mapped IP
device.
For example, if you configure a NAT rule to forward traffic from the WAN to a LAN server,
enabling NAT loopback allows users connected to other interfaces to also access the
server. For LAN users, the UAG uses the LAN interface’s IP address as the source address
for the traffic it sends to the LAN server. See
NAT Loopback on page 192
for more details.
If you do not enable NAT loopback, this NAT rule only applies to packets received on the
rule’s specified incoming interface.
Firewall
By default the firewall blocks incoming connections from external addresses. After you
configure your NAT rule settings, click the
Firewall
link to configure a firewall rule to
allow the NAT rule’s traffic to come in.
The UAG checks NAT rules before it applies To-Device firewall rules, so To-Device firewall
rules do not apply to traffic that is forwarded by NAT rules. The UAG still checks other
firewall rules according to the source IP address and mapped IP address.
OK
Click
OK
to save your changes back to the UAG.
Cancel
Click
Cancel
to return to the
NAT
summary screen without creating the NAT rule (if it is
new) or saving any changes (if it already exists).
Table 77
Configuration > Network > NAT > Add (continued)
LABEL
DESCRIPTION