User`s guide

Chapter 13 Network Address Translation (NAT) Screens
LAN-Cell 2 User’s Guide
304
Figure 182 NAT Application With IP Alias
Port Restricted Cone NAT
LAN-Cell ProxiOS version 4.00 and later uses port restricted cone NAT. Port restricted cone
NAT maps all outgoing packets from an internal IP address and port to a single IP address and
port on the external network. In the following example, the LAN-Cell maps the source address
of all packets sent from internal IP address 1 and port A to IP address 2 and port B on the
external network. A host on the external network (IP address 3 and Port C for example) can
only send packets to the internal host if the internal host has already sent a packet to the
external host’s IP address and port.
A server with IP address 1 and port A sends packets to IP address 3, port C and IP address 4,
port D. The LAN-Cell changes the servers IP address to 2 and port to B.
Since 1, A has already sent packets to 3, C and 4, D, they can send packets back to 2, B and the
LAN-Cell will perform NAT on them and send them to the server at IP address 1, port A.
Packets have not been sent from 1, A to 4, E or 5, so they cannot send packets to 1, A.