P-661HW-D Series Support Notes
When Prestige acting as SUA receives a packet from a local client destined for
the outside Internet, it replaces the source address in the IP packet header
with its own address and the source port in the TCP or UDP header with
another value chosen out of a local pool. It then recomputes the appropriate
header checksums and forwards the packet to the Internet as if it is originated
from Prestige using the IP address assigned by ISP. When reply packets from
the external Internet are received by Prestige, the original IP source address
and TCP/UDP source port numbers are written into the destination fields of the
packet (since it is now moving in the opposite direction), the checksums are
recomputed, and the packet is delivered to its true destination. This is because
SUA keeps a table of the IP addresses and port numbers of the local systems
currently using it.
10. What is the difference between SUA and Full Feature NAT?
When you edit a remote node in Web Configurator, Advanced Setup,
Network
-> Remote Node -> Edit,
there will be three options for you:
•
None
•
SUA Only
•
Full Feature
SUA
(Single User Account) in previous ZyNOS versions is a NAT set with 2
rules:
Many-to-One
and
Server
. With SUA, 'visible' servers had to be mapped
to different ports, since the servers share only one global IP.
The P-661HW-D now has
Full Feature NAT
which supports five types of
IP/Port mapping: One to One, Many to One, Many to Many Overload, Many to
Many No Overload and Server. You can make special application when you
select
Full Feature NAT
. For example: With multiple global IP addresses,
multiple severs using the same port (e.g., FTP servers using port 21/20) are
allowed on the LAN for outside access.
The P-661HW-D supports NAT sets on a remote node basis. They are
reusable, but only one set is allowed for each remote node. The P-661HW-D
supports 8 sets since there are 8 remote nodes.
By fatory default, the NAT is select as
SUA
in Web Configurator, Advanced
Setup,
Network -> NAT -> General -> NAT Setup.
11. Is it possible to access a server running behind SUA from the outside
Internet? How can I do it?
Yes, it is possible because P-661HW-D delivers the packet to the local server
by looking up to a SUA server table. Therefore, to make a local server
9
All contents copyright © 2006 ZyXEL Communications Corporation.