Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
8-22
Configuring Network Address Translation (NAT)
Configuring NAT
Configuring NAT
To configure NAT, follow these steps:
1. Enable routing.
See “IP Settings” on page 6-3 of Chapter 6: IP Services—IP Settings,
DHCP, and DNS.
2. Define interfaces as inside or outside interfaces.
When you create a NAT definition, you will select whether this definition
applies to inside or outside traffic. To do so, you must know which
Wireless Edge Services xl Module interfaces connect to inside networks
and which to outside networks. See “Defining Interfaces as Outside or
Inside” on page 8-22.
3. Configure one or both types of NATs:
Dynamic translation—based on ACLs, which permit or deny NAT
based on IP addresses; as the ACL configuration changes, the NAT
configuration changes as well.
Static translation—configured to specific IP addresses and ports;
any configuration changes are made within the NAT configuration
itself.
Defining Interfaces as Outside or Inside
NAT configurations have no effect until you map interfaces to NAT by defining
particular interfaces as outside or inside. For example, when traffic arrives on
an inside interface, the module applies the configurations created for inside
NAT (as long as the traffic matches the specifications for that NAT definition).
Note NAT applies to traffic that arrives on an interface. NAT does not affect traffic
sent from an interface.
To define an interface as outside or inside, complete these steps:
1. Select Security > NAT and click the Interfaces tab.