Technical Documentation

Configuring Network Address Translation (NSM Procedure)

Network Address Translation (NAT) is a mechanism for concealing a set of host addresses on a private network behind a pool of public addresses. It can be used as a security measure to protect the host addresses from direct targeting in network attacks.

To configure NAT in NSM:

  1. In the navigation tree select Device Manager > Devices.
  2. In the Devices list, double-click the device to select it.
  3. In the Configuration tab, expand Services > Nat.
  4. Add or modify the settings as specified in Table 1.
  5. Click one:
    • OK—To save the changes.
    • Cancel—To cancel the modifications.

Table 1: NAT Configuration Details

Task Your Action

Enable multicast filters on Ethernet interfaces when IPv6 NAT is used for neighbor discovery.

  1. Click Ipv6 Multicast Interfaces next to Nat.
  2. Click Add new entry next to Ipv6 Multicast Interfaces.
  3. From the Name list, select All to enable filters on all interfaces.
  4. Select Interface name to enable filters on a specific interface only.
  5. In the Comment box, enter the comment.
  6. Select the Disable check box to disable filters on the specified interfaces.

Specify the NAT name and properties.

  1. Click Pool next to Nat.
  2. Click Add new entry next to Pool.
  3. In the Name box, enter the identifier for the Nat address pool.
  4. In the Comment box, enter the comment.
  5. Expand pool.
  6. Click Address next to pool.
  7. Click Add new entry next to Address.
  8. In the Name box, enter an IPv4 or IPv6 prefix value.
  9. In the Comment box, enter the comment.

Configure the NAT pool address range.

  1. Click Address Range next to pool.
  2. Click Add new entry next to Address Range.
  3. In the Low box, enter the lower boundary for the IPv4 or IPv6 address range.
  4. In the High box, enter the upper boundary for the IPv4 or IPv6 address range.
  5. In the Comment box, enter the comment.

Configure Packet gateway Control Protocol (PGCP).

  1. Click Pgcp next to pool.
  2. In the Comment box, enter the comment.
  3. Click the Remotely Controlled check box to configure the addresses and ports in a NAT pool to be remotely controlled by the gateway controller.
  4. From the Ports Per Session list, select the number of ports to be enabled.

    Note: The ports per session should be either 2 or 4.

  5. Expand Pgcp.
  6. Click Hint next to Pgcp.
  7. Click Add new entry next to Hint.
  8. In the dialog box, enter an alphanumeric string of up to 3 characters that the BGF uses to match with a termination hint located in the Direction field of a nonstandard termination ID.

Configure addresses and ports for use in NAT Rules.

  1. Click Port next to pool.
  2. In the Comment box, enter the comment.
  3. Expand Port.
  4. Click Automatic next to Port.
  5. Select one of the following:
    • automatic—To configure Router-assigned port.
    • range—To specify a range with minimum and maximum values.

      Range: 0 through 65535

Specify the rule the router uses when applying this service.

  1. Click Rule next to Nat.
  2. Click Add new entry next to Rule.
  3. In the Name box, enter the Identifier for the collection of terms that comprise this rule.
  4. In the Comment box, enter the comment.
  5. From the Match Direction list, select the direction in which the rule match is applied.
  6. Expand Rule.
  7. Click Term next to Rule.
  8. Click Add new entry next to Term.
  9. In the Name box, enter the identifier for the term.
  10. In the Comment box, enter the comment.
  11. Expand term.
  12. Click From next to term.
  13. In the Comment box, enter the comment.
  14. Expand From.
  15. From the listed match conditions, select the ones that are applicable for Nat.

    The match conditions listed are Application Sets, Applications, Destination Address, Destination Address Range, Destination Prefix List, Source Address, Source Address Range, and Source Prefix List.

  16. Click Then next to From.
  17. Expand Then.
  18. In the Comment box, enter the comment.
  19. Select the Syslog check box to enable system logging.
  20. Click No Translation next to Then.
  21. Select one of the following:
    • no-translation—To specify that traffic is not to be translated.
    • translated—To define properties for translated traffic.

Specify the rule set the router uses when applying this service.

  1. Click Rule Set next to Nat.
  2. Click Add new entry next to Rule Set.
  3. In the Name box, enter an identifier for the collection of rules that constitute this rule set.
  4. In the Comment box, enter the comment.
  5. Expand rule-set.
  6. Click Rule next to rule-set.
  7. Click Add new entry next to Rule.
  8. From the Name list, select the identifier for the collection of terms that comprise this rule.
  9. In the Comment box, enter the comment.

Published: 2009-08-23