Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
8-30
Configuring Network Address Translation (NAT)
Configuring NAT
Table 8-5. Determining the IP Address for the Local Address Field
For example, for source NAT, enter the configured IP address
assigned to a device in its own network. This address is typically
allocated out of a private address space.
b. The Local Port field is not available for source NAT.
5. In the After Translation section, specify the IP address to which the Wireless
Edge Services xl Module should translate the source address:
a. In the Global Address field, enter the IP address as it should appear
after translation.
See Table 8-6 for guidelines on specifying this address.
Table 8-6. Determining the IP Address for the Global Address Field
Make sure to enter a valid IP address on this Wireless Edge Services
xl Module. Select an address that is valid in the network to which the
traffic is destined. For example, if you are configuring source NAT for
a wireless device, enter an IP address on a VLAN tagged on the uplink.
b. The Global Port field is not available for source NAT. The Wireless Edge
Services xl Module automatically assigns a port to the translated
packet.
6. Click the OK button.
The static NAT definition is now listed on the Security > NAT > Static Translation
screen. Remember: the translation does not take effect unless you define an
interface as the type on which you configured static source NAT. (See “Defin-
ing Interfaces as Outside or Inside” on page 8-22.)
Interface Type Address Type IP Address for the Local Address Field
Inside (Private) Source IP address of an inside device as it appears on the
inside network
Outside (Public) Source IP address of an outside device as it appears on the
outside network
Interface Type Address Type IP Address for the Global Address Field
Inside (Private) Source IP address of an inside device as it should appear
on the outside network
Outside (Public) Source IP address of an outside device as it should
appear on the inside network