Specifications
Why Would I Use NAT in My Network?
September 08, 2010 Page 2 of 18
Why Would I Use NAT in My Network?
EnterasyssupportforNATprovidesapracticalsolutionfororganizationswhowishtostreamline
theirIPaddressingschemes.NAToperatesonarouterconnectingaprivatenetworktoapublic
network,simplifyingnetworkdesignandconservingIPaddresses.NATcanhelporganizations
mergemultiplenetworkstogetherandenhancenetworksecurity by:
•Helpingtopreventmaliciousactivityinitiatedbyoutsidehostsfromenteringthecorporate
network
•Improvingthereliabilityoflocalsystemsbystoppingworms
•Augmentingprivacybykeepingprivateintranetaddresseshiddenfromviewofthepublic
internet,therebyinhibitingscans
• LimitingthenumberofIPaddressesusedforprivateintranetsthatare
requiredtobe
registeredwiththeInternetAssignedNumbersAuthority(IANA)
• ConservingthenumberofglobalIPaddressesneededbyaprivateintranet
How Can I Implement NAT?
ToimplementNATinyournetwork:
•EnableNATonboththeinside(local)andoutside(public)interfacestobeusedfortranslation
•Ifyouintendtouseinsidesourceaddressdynamictranslation(see“DynamicInsideAddress
Translations”onpage 5fordetails):
–Defineanaccess‐listofinsideaddresses
–DefineaNATaddress
poolofoutsideaddresses
–Enabledynamictranslationofinsideaddressesspecifyinganaccess‐listofinside
addressesandaNATaddresspoolofoutsideaddresses
– OptionallyconfigureoverloadforNAPT(defaultstoNAT)
– Optionallyspecifytheinterfacetowhichtranslationsareapplied
•Ifyouintendtouseinsidesourceaddressstatictranslation
(see“StaticInsideAddress
Translation”onpage 3fordetails),enableinsidesourceaddressstatictranslationinthe
appropriateNAT orNAPTcontext
• OptionallychangetheNATFTPcontrolportfromitsdefaultof21
• Optionallyenableforceflowstoforceallflowstobetranslatedbetweenoutsideandinside
addresses
• Optionally
modifymaximumallowedentriesandNATtranslationtimeoutvalues