Kerio Tech KERIO WINROUTE FIREWALL 6 User Manual

Page 84

Advertising
background image

Chapter 7

Traffic Policy

84

Figure 7.14

Traffic rule — selecting an action

Translation

Source or/and destination IP address translation.

Source IP address translation (NAT — Internet connection sharing)

The source IP address translation can be also called IP masquerading or Internet connection

sharing. The source (private) IP address is substituted by the IP address of the interface

connected to the Internet in outgoing packets routed from the local network to the Internet.

Therefore, the entire local network can access the Internet transparently, but it is externally

considered as one host.

Source address translation is used in traffic rules applied to traffic from the local private

network to the Internet. In other rules (traffic between the local network and the firewall,

between the firewall and the Internet, etc.), NAT is meaningless. For detailed information and

examples of rules, refer to chapter

7.4

.

For source address translation, WinRoute offers these options:

Automatic IP address selection

By default, in packets sent from the LAN to the Internet the source IP address will be

replaced by IP address of the Internet interface of the firewall through which the packet

is sent. This IP address translation method is useful in the general rule for access from the

LAN to the Internet (see chapter

7.4

), because it works correctly in any Internet connection

configuration and for any status of individual links (for details, see chapter

6

).

If WinRoute works in the mode of network traffic load balancing (see chapter

6.4

), you

can select a method which will be used for spreading the traffic between the LAN and the

Internet over individual Internet links:

Load balancing per host — all traffic from the specific host (client) in the LAN will

always be routed via the same Internet link. All connections from the client will be

established from the same source IP address (the public address of the particular

interface of the firewall). This method is set as default, because it guarantees the

same behavior as in case of clients connected directly to the Internet. However,

Advertising