Prestige 202 ISDN Router
7-2
NAT
l
NAT can provide firewall protection if you do not specify a server (for Many-to-One and
Many-to-Many Overload mapping) and all incoming inquiries will be filtered out by your
Prestige.
l
UDP and TCP packets can be routed. In addition, partial ICMP, including echo and traceroute,
is supported.
7.1.2 How NAT Works
Each packet consists of two addresses – a source address and a destination address. For outgoing
packets, the ILA is the source address on the LAN, and the IGA is the source address on the WAN.
For incoming packets, the ILA is the destination address on the LAN, and the IGA is the
destination address on the WAN. The term “Inside” refers to the set of networks that are subject to
translation. Network Address Translation operates by mapping private (local) IP addresses to
globally unique ones required for communication with hosts on other networks. It replaces the
original IP source address (and TCP or UDP source port numbers for Many-to-One and Many-to-
Many Overload NAT mapping) and then forwards each packet to the Internet ISP, thus making
them appear as if they had come from the NAT system itself (e.g., the Prestige). The Prestige keeps
track of the original addresses and port numbers so incoming reply packets can have their original
values restored. The following diagram illustrates this.
Figure 7-1 How NAT Works
Summary of Contents for ZyXEL Prestige 202
Page 1: ...Prestige 202 User s Guide Version 2 50 June 2000 ZyXEL TOTAL INTERNET ACCESS SOLUTION ...
Page 2: ......
Page 6: ...Prestige 202 ISDN Router iv CE Marking ...
Page 29: ......
Page 108: ......
Page 140: ......
Page 200: ......