TMS zl Management and Configuration Guide ST.1.1.100226
5-3
Network Address Translation
NAT Operations
NAT Operations
In routing mode the TMS zl Module can apply NAT to network traffic. (Monitor
mode does not support NAT.) While the module’s firewall provides the NAT
capability, the NAT policies are entirely separate from the firewall access
policies for increased flexibility. This section describes the types of NAT that
the TMS zl Module can perform. This information is only intended to inform
you of the module’s capabilities. When you configure NAT, you do not need to
determine the specific type of source or destination NAT that you require.
Once you configure the source, destination, and NAT addresses, the module
dynamically assigns the type of source or destination NAT.
The module can perform the following types of NAT:
■ Source NAT
• One-to-one
• Many-to-one
• Many-to-many
■ Destination NAT
• One-to-one with optional port forwarding and optional port address
translation (PAT)
• Many-to-one with optional port forwarding and optional PAT
■ Exclusion NAT
Source NAT
With source NAT the TMS zl Module translates the source IP address of a
packet to a new IP address, which is valid in the network to which the packet
is destined. Traditionally, source NAT is applied to connections from the
private network to the public network, where the private source IP address is
converted into a public NAT IP address. However, source NAT can also be
applied within the network to convert a private network address into another
private network address.