Configure Port Forwarding/1:1 NAT in Site Configuration > Firewall tab
Prerequisites:
-
Public IP Block of /30 or larger assigned to site
Can be viewed in Site Configuration → LAN Settings
-
Static private IP assigned to LAN Client
See ‘View and Manage LAN Clients’
To complete configuration:
Under the NAT Rules (1:1) Rules section, click “+ New NAT rule” to configure a new 1:1 NAT rule
-
Configure the following items:
Name (optional)
-
Public IP (required)
Drop down will show all available and assigned Public IP’s
-
LAN IP (required)
Drop down will show all available static LAN Clients
-
Add protocol/port rule(s) (optional)
Protocol (TCP, UDP, TCP/UDP, ICMP, ALL)
Action (Allow, Deny)
Ports
Allowed Remote IP’s
Can remove individual protocol/port rules via ‘Remove rule’ button
Once all required items are configured, click ‘Add NAT rule’ to complete setup
To manage existing NAT Rules (1:1) in table:
Hits counter shows number of times a rule has been used
Edit existing rule
Delete existing rule
For deeper troubleshooting, review the site Logs → Firewall Logs for additional details.
What is the 1:1 NAT implementation that Bigleaf supports?
IPv4 to IPv4 only.
-
One specific public IP address maps to one specific private IP address.
NAT routes are 1-to-1 only.
NAT routes are not 1-to-many. We do not support translating sets or pools of IP addresses.
-
Standard 1:1 NAT translation, which includes:
Outbound SNAT.
Inbound DNAT.
Cisco Meraki calls this “1:1 NAT.”
Cisco calls this “layer-2 NAT” for at least some of their products.
HP/Juniper calls this “inline NAT.”
-
Users may configure 1:1 NAT on all IPs in a public IP block.
There is no concept of network IP or broadcast IP.
-
See also:
Definitions
-
1:1 NAT route (a.k.a. “1-to-1” NAT route): A mapping of one public static IP address to one private static IP address.
In the BCC this is called a “NAT rule.” A NAT route does nothing on its own; it is combined with its NAT rules to create the resulting iptables rules.
-
1:1 NAT rule: A filter allowing only specific traffic to be translated in accordance with a 1:1 NAT route.
In the BCC this is called a “port / protocol rule” under a “NAT rule.”
DNAT: Destination NAT. Translating the destination IP address of traffic. Port forwarding is DNAT for specific ports only.
SNAT: Source NAT. Translating the source IP address of traffic. This is commonly used to provide a subnet of private IP addresses for use on a LAN.
-
Static IP: An overloaded term with two definitions here as follows.
LAN client static IP: A DHCP LAN client that has been configured statically, so it retain its private IP address indefinitely, even when the client is down.
Public static IP: An IP address from one of the customer’s available public IP blocks.
Comments
0 comments
Article is closed for comments.