Specifications
NAT Overview
September 08, 2010 Page 8 of 18
DNS, FTP and ICMP Support
NATworkswithDNSbyhavingtheDNSApplicationLayerGateway(ALG)translateanaddress
thatappearsinaDomainNameSystemresponsetoanameorinverselookup.
NATworkswithFTPbyhavingtheFTPALGtranslatetheFTPcontrolpayload.BothFTPPORT
CMDpacketsandPASVpackets,
containingIPaddressinformationwithinthedataportion,are
supported.TheFTPcontrolportisconfigurable.
TheNATimplementationalsosupportsthetranslationoftheIPaddressembeddedinthedata
portionoffollowingtypes ofICMPerrormessage:destinationunreachable(type3),sourcequench
(type4),redirect(type5),timeexceeded(type11)
andparameterproblem(type12).
NAT Timeouts
Themaximumtimeoutvalueinsecondsperflowisconfigurableforthefollow ingflowtypes:
• Dynamictranslation
•UDPandTCP
•ICMP
•DNS
•FTP
NAT Router Limits
Routerparameterssuchasthenumberofbindingsandcachesizeusevaluablememoryresources
thataresharedbyotherroutingfunctionssuchasLSNATandTWCBonafirst‐comefirst‐served
basis.Bydefaultthesesettingsaresettomaximumvalues.Byloweringthemaximumlimitfor
affectedparameters,
theresourcedeltabetweenthenewlimitandthemaximumvalueforthat
parameterwillbeavailabletootherroutingfunctionssuchasLSNATandTWC B.Maximum
limitscanbesetorclearedforthefollowingNATrelatedrouterparameters:
•NATbindings
•Cachesize
• Dynamicmappingconfigurations
•Staticmappingconfigura tions
•Interfaceconfigurations
•Global
Addressconfigurations
•Globalportconfigurations
Note: The maximum number of bindings and cache available should only be modified to assure
availability to functionalities that share these resources such as TWCB, NAT and LSNAT. It is
recommended that you consult with Enterasys customer support before modifying these parameter
values.