User`s manual
EDR-G903/G902 Features and Functions
3-28
Routing Table
The Routing Table page shows all routing entries.
All Routing Entry List
Setting Description Factory Default
All Show all routing entries N/A
Connected Show connected routing entries N/A
Static Show Static routing entries N/A
RIP Show RIP routing entries N/A
Others Show others routing entries N/A
Network Address Translation (NAT)
NAT Concept
NAT (Network Address Translation) is a common security function for changing the IP address during Ethernet
packet transmission. When the user wants to hide the internal IP address (LAN) from the external network
(WAN), the NAT function will translate the internal IP address to a specific IP address, or an internal IP address
range to one external IP address. The benefits of using NAT include:
• Uses the N- 1 or Port forwarding Nat function to hide the Internal IP address of a critical network or device
to increase the level of security of industrial network applications.
• Uses the same private IP address for different, but identical, groups of Ethernet devices. For example,
1-to-1 NAT makes it easy to duplicate or extend identical production lines.
NOTE
The NAT function will check if incoming or outgoing packets match the policy. It starts by checking
the packet
with the first policy (Index=1); if the packet matches this policy, the EtherDevice Router will translate the
address immediately and then start checking the next packet. If the packet does not match this policy,
it will
check with the next policy.
NOTE The maximum number of NAT policies for the EtherDevice Router is 128.
N-to-1 NAT
If the user wants to hide the Internal IP address from users outside the LAN, the easiest way is to use the
N-to-1 (or N-1) NAT function. The N-1 NAT function replaces the source IP Address with an external IP address,
and adds a logical port number to identify the connection of this internal/external IP address. This function is
also called “Network Address Port Translation” (NAPT) or “IP Masquerading.”
The N-1 NAT function is a one way connection from an internal secure area to an external non-secure area. The
user can initialize the connection from the internal to the external network, but may not be able to initialize the
connection from the external to the internal network.










