User guide

NAT support on AT-iMG Models Network address translation - NAT
4-135
iMG/RG Software Reference Manual (IPNetwork Functions)
static NAT: defines a fixed address translation from the internal network to the external network
dynamic NAT: translates from a pool of local IP addresses to a pool of global IP addresses
NAT provides a mechanism for reducing the need for globally unique IP addresses. It allows you to use
addresses that are not globally unique on your internal network and translate them to a single globally unique
external address
FIGURE 4-3 Address Conservation Using NAT
4.4.2 NAT support on AT-iMG Models
AT-iMG Models NAT module is designed to provide the following features:
Global IP address pools
Reserved mappings
Application level gateways (algs)
NAT services are available between External security interface and Internal Security interfaces.
In order to access NAT services, the NAT module must be enabled between a a pair of interfaces by using the
NAT ENABLE command and assigning an arbitrary name to this relationship.
Note: Before enabling NAT, the Security module must be already enabled using SECURITY ENABLE
command.
See XREF_HERESecurity section for details regarding security interfaces.
Global IP Address Pools
A Global Address Pool is a pool of addresses seen from the external network. By default, each external inter-
face creates a Global Address Pool with a single address – the address assigned to that interface.
10.0.0.3
10.0.0.2
24.2.249.4
Unit
(Router with NAT)
10.0.0.4
10.0.0.1
Internet