User Manual

Enterasys X-Pedition User Reference Manual 333
Configuration Examples
The first step is to create the interfaces:
Next, define the interfaces to be NAT “inside” or “outside”:
Then, define the NAT dynamic rules by first creating the source ACL pool and then configuring the
dynamic bindings:
Using Dynamic NAT
Dynamic NAT can be used when the local network (inside network) is going to initialize the
connections. It creates a binding at run time when a packet is sent from a local network, as defined
by the NAT dynamic local ACl pool. The network administrator does not have to worry about the
way in which the bindings are created; the network administrator just sets the pools and the XP
automatically chooses a free global IP from the global pool for the local IP.
Dynamic bindings are removed when the flow count for that binding goes to zero or the timeout has
been reached. The free globals are used again for the next packet.
A typical problem is that if there are more local IP addresses as compared to global IP addresses in
the pools, then packets will be dropped if all the globals are used. A solution to this problem is to
use PAT with NAT dynamic. This is only possible with TCP or UDP protocols.
interface create ip 10-net address-netmask 10.1.1.1/24 port et.2.1
interface create ip 192-net address-netmask 192.50.20.1/24 port et.2.2
nat set interface 10-net inside
nat set interface 192-net outside
acl lcl permit ip 10.1.1.0/24
nat create dynamic local-acl-pool lcl global-pool 192.50.20.0/24