4 dynamic nat with dns, Dynamic nat with dns -9, Figure 21-4 dynamic address binding with dns -9 – Riverstone Networks WICT1-12 User Manual

Page 495

Advertising
background image

Riverstone Networks RS Switch Router User Guide Release 8.0 21-9

Network Address Translation Configuration

Configuration Examples

3.

Then, define the NAT dynamic rules by first creating the source ACL pool and then configuring the
dynamic bindings:

Using Dynamic NAT with IP Overload

Dynamic NAT with IP overload can be used when the local network (inside network) will be initializing the
connections using TCP or UDP protocols. It creates a binding at run time when the packet comes from a local network
defined in the NAT dynamic local ACL pool. The difference between the dynamic NAT and dynamic NAT with PAT
is that PAT uses port (layer 4) information to do the translation. Hence, each global IP has about 4000 ports that can
be translated. NAT on the RS uses the standard BSD range of ports from 1024-4999 which is fixed and cannot be
configured by the user. The network administrator does not have to worry about the way in which the bindings are
created; he/she just sets the pools and the RS automatically chooses a free global IP from the global pool for the local
IP.

Dynamic bindings are removed when the flow count goes to zero or the timeout has been reached. The removal of
bindings frees the port for that global and the port is available for reuse. When all the ports for that global are used,
then ports are assigned from the next free global. If no more ports and globals are available, the packets will be
dropped.

21.8.4

Dynamic NAT with DNS

The following example configures a DNS dynamic address binding for outside address 192.50.20.2-192.50.20.9 to
inside addresses 10.1.1.0/24:

Figure 21-4 Dynamic address binding with DNS

acl lcl permit ip 10.1.1.0/24

nat create dynamic local-acl-pool lcl global-pool 192.50.20.1-192.50.20.3

enable-ip-overload

HW



HW



*OREDO ,QWHUQHW

,3 QHWZRUN 

5RXWHU

LQWHUIDFH QHW

LQWHUIDFH QHW

'16

'16 VHUYHU VWDWLF ELQGLQJ RI  WR 







6HUYHU

Advertising