F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices NAT and ALG Configuration Guide-6PW100
Table Of Contents
- Title Page
- Table of Contents
- Configuring NAT
- Overview
- Configuration guidelines
- Configuring NAT in the Web interface
- Recommended configuration procedure
- Creating an address pool
- Configuring dynamic NAT on an interface
- Creating a static address mapping
- Enabling static NAT on an interface
- Configuring an internal server
- Configuring ACL-based NAT on the internal server
- Configuring DNS mapping
- NAT configuration example
- Internal server configuration example
- Configuring NAT at the CLI
- NAT configuration task list
- Configuring static NAT
- Configuring dynamic NAT
- Configuring an internal server
- Configuring ACL-based NAT on an internal server
- Configuring DNS mapping
- Displaying and maintaining NAT
- One-to-one static NAT configuration example
- Dynamic NAT configuration example
- Common internal server configuration example
- NAT DNS mapping configuration example
- Troubleshooting NAT
- Configuring NAT-PT
- Feature and hardware compatibility
- Overview
- NAT-PT configuration task list
- Configuration prerequisites
- Enabling NAT-PT
- Configuring a NAT-PT prefix
- Configuring IPv4/IPv6 address mappings on the IPv6 side
- Configuring IPv4/IPv6 address mappings on the IPv4 side
- Setting the ToS field after NAT-PT translation
- Setting the traffic class field after NAT-PT translation
- Configuring static NAPT-PT mappings of IPv6 servers
- Displaying and maintaining NAT-PT
- NAT-PT configuration examples
- Troubleshooting NAT-PT
- NAT444
- Configuring ALG
- Support and other resources
- Index

28
Ste
p
Command
Remarks
3. Configure a common
internal server.
• nat server [ index | acl-number ] protocol pro-type global
{ global-address | current-interface | interface
interface-type interface-number } [ global-port ] inside
local-address [ local-port ] [ vpn-instance local-name ]
• nat server [ index | acl-number ] protocol pro-type global
{ global-address | current-interface | interface
interface-type interface-number } global-port1 global-port2
inside local-address1 local-address2 local-port
[ vpn-instance local-name ]
Use either
command.
To configure a common internal server (2):
Ste
p
Command
Remarks
1. Enter system view. system-view N/A
2. Enter interface view.
interface interface-type interface-number N/A
3. Configure a common
internal server.
• nat server [ index | acl-number ] protocol pro-type
global { global-address | current-interface |
interface interface-type interface-number }
[ global-port ] [ vpn-instance global-name ] inside
local-address [ local-port ] [ vpn-instance
local-name ] [ track vrrp virtual-router-id ]
• nat server [ index | acl-number ] protocol pro-type
global { global-address | current-interface |
interface interface-type interface-number }
global-port1 global-port2 [ vpn-instance
global-name ] inside local-address1 local-address2
local-port [ vpn-instance local-name ] [ track vrrp
virtual-router-id ]
Use either
command.
To configure a common internal server (3):
Ste
p
Command
1. Enter system view.
system-view
2. Enter interface view. interface interface-type interface-number
3. Configure a common
internal server.
nat server [ index | acl-number ] protocol pro-type global { global-address
global-port1 global-port2 inside local-address1 local-address2 local-port
[ vpn-instance local-name ] [ track vrrp virtual-router-id ] | current-interface
[ global-port ] inside local-address [ local-port ] [ vpn-instance local-name ]
[ remote-host host-address ] [ lease-duration lease-time ] [ description string ] }
59BConfiguring ACL-based NAT on an internal server
This feature maps the destination address of an ACL-permitted packet to the internal server address or the
internal server IP address/port number.
To configure ACL-based NAT on an internal server: