R3303-HP 6600/HSR6600 Routers Layer 3 - IP Services Command Reference
129
Usage guidelines
A device can support a maximum of 16 DNS mappings.
Examples
# A company provides Web service to external users. The domain name of the internal server is
www.server.com, and the public IP address is 202.112.0.1. Configure a DNS mapping, so that internal
users can access the Web server using its domain name.
<Sysname> system-view
[Sysname] nat dns-map domain www.server.com protocol tcp ip 202.112.0.1 port www
Related commands
display nat dns-map
nat outbound
Use nat outbound or nat outbound acl-number to associate an ACL with the IP address of an interface
and enable Easy IP.
Use undo nat outbound to remove an association.
Syntax
nat outbound [ acl-number ] [ address-group group-number [ vpn-instance vpn-instance-name ]
[ no-pat ] ] [ track vrrp virtual-router-id ]
undo nat outbound [ acl-number ] [ address-group group-number [ vpn-instance vpn-instance-name ]
[ no-pat ] ] [ track vrrp virtual-router-id ]
Views
Interface view
Default command level
2: System level
Parameters
acl-number: Specifies an ACL number in the range of 2000 to 3999.
address-group group-number: Specifies an address pool for NAT. The value range for the group-number
argument is 0 to 127. If you do not specify any address is specified, the IP address of the interface is used
as the translated IP address. That is, Easy IP is enabled.
vpn-instance vpn-instance-name: Specifies the MPLS L3VPN to which the addresses of the address pool
belong. The vpn-instance-name argument is a case-sensitive string of 1 to 31 characters. With this option,
inter-VPN access through NAT is supported. Without this option, the addresses in the address pool do
not belong to any VPN.
no-pat: Indicates that no many-to-many NAT is implemented. If this keyword is not configured,
many-to-one NAT is implemented using the TCP/UDP port information.
track vrrp virtual-router-id: Associates address translation on a specific outbound interface with a VRRP
group. The virtual-router-id argument indicates the number of the VRRP group in the range of 1 to 255.
Without this argument specified, no VRRP group is associated.
Usage guidelines
You can configure multiple associations or use the undo command to remove an association on an
interface that serves as the egress of an internal network to the external network.










