Avaya Configuring BFE Services Instrukcja Użytkownika

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Nie Avaya Configuring BFE Services. Avaya Configuring BFE Services User's Manual Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 258
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów

Podsumowanie treści

Strona 1 - Configuring GRE, NAT, RIPSO

BayRS Version 14.20Part No. 308625-14.20 Rev 00October 2000600 Technology Park DriveBillerica, MA 01821-4130Configuring GRE, NAT, RIPSO, and BFE Serv

Strona 2 - Statement of Conditions

x308625-14.20 Rev 00Configuring Sample Bidirectional NAT Using the BCC ... B-3Information Used in Bid

Strona 3

Configuring GRE, NAT, RIPSO, and BFE Services2-52308625-14.20 Rev 00Step 4. Configure a NAT router interface to a device in each domain that will use

Strona 4

Configuring Network Address Translation308625-14.20 Rev 002-53For example, the following command sets the name-server parameter to IP address 192.32.7

Strona 5 - Contents

Configuring GRE, NAT, RIPSO, and BFE Services2-54308625-14.20 Rev 00Here is a look at what has been configured for DNS proxy, accepting default values

Strona 6

Configuring Network Address Translation308625-14.20 Rev 002-55unnumbered-circuit-name {}use-translation-pool outboundThe type parameter is a read-only

Strona 7

Configuring GRE, NAT, RIPSO, and BFE Services2-56308625-14.20 Rev 00Using Site ManagerTo use Site Manager to configure a dynamic bidirectional network

Strona 8

Configuring Network Address Translation308625-14.20 Rev 002-57Install DNS server on a device that has a public address connection to the router that w

Strona 9

Configuring GRE, NAT, RIPSO, and BFE Services2-58308625-14.20 Rev 00Step 4. Configure RIP2 on the router IP interfaces and on each device that will us

Strona 10 - 308625-14.20 Rev 00

Configuring Network Address Translation308625-14.20 Rev 002-59Steps 5, 6, 7: Configure NAT on an interface, specify a domain name, and identify a DNS

Strona 11

Configuring GRE, NAT, RIPSO, and BFE Services2-60308625-14.20 Rev 00* If, for some reason, you decide not to configure DNS proxy at this point, see th

Strona 12

Configuring Network Address Translation308625-14.20 Rev 002-61To configure a source address filter, complete the following tasks:Step 9. Configuring a

Strona 13

308625-14.20 Rev 00 xiFiguresFigure 1-1. Simple GRE Tunnel Components ...1-3Figure 1-2. GRE

Strona 14

Configuring GRE, NAT, RIPSO, and BFE Services2-62308625-14.20 Rev 00To configure a translation pool, complete the following tasks:Site Manager Procedu

Strona 15

Configuring Network Address Translation308625-14.20 Rev 002-63Step 10. Configure DNS client on each device in the domains that will initiate address t

Strona 16 - Text Conventions

Configuring GRE, NAT, RIPSO, and BFE Services2-64308625-14.20 Rev 00Where to Go NextThe instructions in “Starting NAT Services and Configuring Transla

Strona 17 - Acronyms

Configuring Network Address Translation308625-14.20 Rev 002-65Customizing NAT Global ParametersTo customize the way NAT operates on a router, modify N

Strona 18 - Related Publications

Configuring GRE, NAT, RIPSO, and BFE Services2-66308625-14.20 Rev 00Enabling and Disabling NAT on the RouterWhen you first configure any router interf

Strona 19 - How to Get Help

Configuring Network Address Translation308625-14.20 Rev 002-67Configuring the Soloist Slot MaskBy default, the router uses any available slot for the

Strona 20

Configuring GRE, NAT, RIPSO, and BFE Services2-68308625-14.20 Rev 00Using Site ManagerTo specify the slots on which NAT can run as a soloist, complete

Strona 21 - Configuring GRE Tunnels

Configuring Network Address Translation308625-14.20 Rev 002-69Logging NAT MessagesBy default, BayRS does not log NAT messages. You can enable the logg

Strona 22 - GRE Concepts and Terminology

Configuring GRE, NAT, RIPSO, and BFE Services2-70308625-14.20 Rev 00Using Site ManagerTo specify the types of log messages that are reported by NAT so

Strona 23 - How GRE Tunneling Works

Configuring Network Address Translation308625-14.20 Rev 002-71Enabling and Disabling the Dynamic Mapping Aging TimerBy default, the router deletes exp

Strona 25

Configuring GRE, NAT, RIPSO, and BFE Services2-72308625-14.20 Rev 00Configuring the Dynamic Mapping Timeout ValueA NAT dynamic mapping (translation en

Strona 26 - Checksum (optional)

Configuring Network Address Translation308625-14.20 Rev 002-73Using the BCCTo configure the timeout period for a dynamic translation entry, navigate t

Strona 27

Configuring GRE, NAT, RIPSO, and BFE Services2-74308625-14.20 Rev 00Customizing a NAT InterfaceThis section includes the following topics:Adding NAT t

Strona 28

Configuring Network Address Translation308625-14.20 Rev 002-75Using Site ManagerTo add NAT to a router IP interface, complete the following tasks:Site

Strona 29

Configuring GRE, NAT, RIPSO, and BFE Services2-76308625-14.20 Rev 008. Click on Yes or click on No:• If you click on Yes, specify an address for DNS S

Strona 30 - Creating a GRE Tunnel

Configuring Network Address Translation308625-14.20 Rev 002-77Disabling and Reenabling NAT on an InterfaceWhen you add NAT to a router interface, NAT

Strona 31

Configuring GRE, NAT, RIPSO, and BFE Services2-78308625-14.20 Rev 00Using Site ManagerTo disable or reenable NAT on an interface, complete the followi

Strona 32

Configuring Network Address Translation308625-14.20 Rev 002-79Deleting NAT from an InterfaceWhen you delete NAT from the last NAT-configured interface

Strona 33

Configuring GRE, NAT, RIPSO, and BFE Services2-80308625-14.20 Rev 00Configuring NAT Static Address TranslationStatic address mapping entries must be u

Strona 34

Configuring Network Address Translation308625-14.20 Rev 002-81Adding a Static Unidirectional Address MappingTo add a static unidirectional mapping, yo

Strona 35

308625-14.20 Rev 00xiiiTablesTable 2-1. Comparing NAT Types SDPT and N-to-1 ...2-5Table 2-2. Sample Conf

Strona 36

Configuring GRE, NAT, RIPSO, and BFE Services2-82308625-14.20 Rev 00Optionally, you can specify either a static next hop or an unnumbered circuit name

Strona 37

Configuring Network Address Translation308625-14.20 Rev 002-83out-domain-name publicstate enabledtranslated-address 199.1.42.200unnumbered-circuit-nam

Strona 38 - <address>

Configuring GRE, NAT, RIPSO, and BFE Services2-84308625-14.20 Rev 00Adding a Static Bidirectional Address MappingFor static bidirectional NAT, you mus

Strona 39

Configuring Network Address Translation308625-14.20 Rev 002-85Similar to static unidirectional mapping, you are mapping a single address to another si

Strona 40

Configuring GRE, NAT, RIPSO, and BFE Services2-86308625-14.20 Rev 00Using the BCCTo add a bidirectional static address mapping on the NAT router, navi

Strona 41 - Customizing a GRE Tunnel

Configuring Network Address Translation308625-14.20 Rev 002-87Examples of Configuring Static Bidirectional NAT to Work with or Independent of DNS Prox

Strona 42

Configuring GRE, NAT, RIPSO, and BFE Services2-88308625-14.20 Rev 004. Choose Static Mapping. The NAT Static Translation List window opens.5. Click on

Strona 43 - 9.9.9.1/255.255.255.0:

Configuring Network Address Translation308625-14.20 Rev 002-89Adding an SDPT Address and Port MappingTo configure NAT SDPT you statically map the addr

Strona 44

Configuring GRE, NAT, RIPSO, and BFE Services2-90308625-14.20 Rev 00translated_address is the public address that you want to map to the original addr

Strona 45

Configuring Network Address Translation308625-14.20 Rev 002-91ip/192.1.2.3/255.0.0.0# nat domain-name publicnat/192.1.2.3#Using Site ManagerBefore you

Strona 47 - Deleting a GRE Tunnel

Configuring GRE, NAT, RIPSO, and BFE Services2-92308625-14.20 Rev 00Disabling and Reenabling a Static Address MappingWhen you add a NAT static address

Strona 48

Configuring Network Address Translation308625-14.20 Rev 002-93Using Site ManagerTo disable or reenable a static address mapping, complete the followin

Strona 49 - Chapter 2

Configuring GRE, NAT, RIPSO, and BFE Services2-94308625-14.20 Rev 00Using Site ManagerTo delete a static address mapping, complete the following tasks

Strona 50 - NAT Concepts

Configuring Network Address Translation308625-14.20 Rev 002-95Configuring NAT Dynamic Address TranslationFor dynamic NAT to work, you must do the foll

Strona 51 - Unidirectional NAT

Configuring GRE, NAT, RIPSO, and BFE Services2-96308625-14.20 Rev 005. Configure a range of addresses as a translation pool. Instructions follow. Dyna

Strona 52 - For this information See

Configuring Network Address Translation308625-14.20 Rev 002-97Adding a Source Address FilterA source address filter is a range of addresses within a d

Strona 53

Configuring GRE, NAT, RIPSO, and BFE Services2-98308625-14.20 Rev 00IP Address and Prefix Length ParameterTo identify an address range for a source ad

Strona 54

Configuring Network Address Translation308625-14.20 Rev 002-99Use the BCC parameter use-translation-pool or the Site Manager parameter Translation Poo

Strona 55

Configuring GRE, NAT, RIPSO, and BFE Services2-100308625-14.20 Rev 00Using the BCCTo configure a source address filter, navigate to the domain name pr

Strona 56

Configuring Network Address Translation308625-14.20 Rev 002-101Examples of specifying a translation pool for a source address filterIf you configure a

Strona 57

308625-14.20 Rev 00xv PrefaceThis guide describes the following services and what you do to start and customize them on a Nortel Networks™ router:• Ge

Strona 58 - Translation Modes

Configuring GRE, NAT, RIPSO, and BFE Services2-102308625-14.20 Rev 00Using Site ManagerTo configure a source address filter, complete the following ta

Strona 59

Configuring Network Address Translation308625-14.20 Rev 002-103Disabling and Reenabling a Source Address FilterWhen you add a source address filter, i

Strona 60

Configuring GRE, NAT, RIPSO, and BFE Services2-104308625-14.20 Rev 00Using Site ManagerTo disable or reenable a source address filter, complete the fo

Strona 61 - show ip

Configuring Network Address Translation308625-14.20 Rev 002-105Deleting a Source Address FilterUse the BCC or Site Manager to delete a source address

Strona 62

Configuring GRE, NAT, RIPSO, and BFE Services2-106308625-14.20 Rev 00Adding a Translation PoolA translation pool is a range of IP addresses that you s

Strona 63

Configuring Network Address Translation308625-14.20 Rev 002-107Using the BCCTo configure a translation pool, navigate to the domain name prompt (for e

Strona 64

Configuring GRE, NAT, RIPSO, and BFE Services2-108308625-14.20 Rev 007. Set the following parameters:• IP Address• Prefix Length• Domain NameClick on

Strona 65

Configuring Network Address Translation308625-14.20 Rev 002-109Disabling and Reenabling a Translation PoolWhen you create a translation pool, it is en

Strona 66

Configuring GRE, NAT, RIPSO, and BFE Services2-110308625-14.20 Rev 00Using Site ManagerTo disable or reenable a translation pool, complete the followi

Strona 67

Configuring Network Address Translation308625-14.20 Rev 002-111Deleting a Translation PoolUse the BCC or Site Manager to delete a translation pool.Usi

Strona 68

Configuring GRE, NAT, RIPSO, and BFE Servicesxvi308625-14.20 Rev 00Text ConventionsThis guide uses the following text conventions:angle brackets (<

Strona 69

Configuring GRE, NAT, RIPSO, and BFE Services2-112308625-14.20 Rev 006. Select the translation pool that you want to delete from the list in the upper

Strona 70

Configuring Network Address Translation308625-14.20 Rev 002-113Configuring NAT N-to-1 TranslationNAT N-to-1 translation allows you to configure a rang

Strona 71

Configuring GRE, NAT, RIPSO, and BFE Services2-114308625-14.20 Rev 00For example, the following command sequence configures the IP address 199.1.42.10

Strona 72

308625-14.20 Rev 003-1 Chapter 3Configuring RIPSO on an IP InterfaceThis chapter describes RIPSO and provides instructions for configuring RIPSO on an

Strona 73

Configuring GRE, NAT, RIPSO, and BFE Services3-2308625-14.20 Rev 00RIPSO Concepts and TerminologyIP routers support the Department of Defense (DoD) Re

Strona 74 - Bidirectional NAT

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-3 You also specify whether the router creates the following types of labels:• An implicit lab

Strona 75

Configuring GRE, NAT, RIPSO, and BFE Services3-4308625-14.20 Rev 00• Octet 4 and beyond identify the protection authorities under whose rules the data

Strona 76 - Domain 2

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-5 • The authority flags in the datagram’s label must include all flags required for the inter

Strona 77

Configuring GRE, NAT, RIPSO, and BFE Services3-6308625-14.20 Rev 00• If the inbound interface does not have an implicit label configured, the router l

Strona 78 - Domain 3

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-7 Specifying the IP Datagram Type for Stripping Security OptionsUse Site Manager to choose th

Strona 79

Preface308625-14.20 Rev 00xvii AcronymsThis guide uses the following acronyms::screen text Indicates system output, for example, prompts and system me

Strona 80 - NAT Implementation Guidelines

Configuring GRE, NAT, RIPSO, and BFE Services3-8308625-14.20 Rev 00Specifying the Outbound Datagram Type Requiring Security LabelsUse Site Manager to

Strona 81

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-9 Specifying the Inbound Datagram Type Requiring Security LabelsUse Site Manager to specify t

Strona 82

Configuring GRE, NAT, RIPSO, and BFE Services3-10308625-14.20 Rev 00Setting the Security Level for IP DatagramsUse Site Manager to specify the minimum

Strona 83

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-11 Choosing Authority Flags in Outbound DatagramsUse Site Manager to specify which authority

Strona 84

Configuring GRE, NAT, RIPSO, and BFE Services3-12308625-14.20 Rev 00Choosing Authority Flags in Inbound DatagramsUse Site Manager to specify which aut

Strona 85

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-13 Supplying Implicit Labels for Unlabeled Inbound DatagramsUse Site Manager to specify wheth

Strona 86

Configuring GRE, NAT, RIPSO, and BFE Services3-14308625-14.20 Rev 00Enabling and Disabling Default Labels for Unlabeled Outbound DatagramsUse Site Man

Strona 87

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-15 Enabling and Disabling Error Labels for Outbound ICMP Error DatagramsUse Site Manager to s

Strona 88 - Site Manager 2-45

Configuring GRE, NAT, RIPSO, and BFE Services3-16308625-14.20 Rev 00RIPSO ExampleThe router in Figure 3-2 has RIPSO configured on all three IP interfa

Strona 89

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-17 Figure 3-2. RIPSO Example1.1.0.11.1.0.21.2.0.1 1.3.0.11.1.0.1Forward outbounddatagram?

Strona 90

Configuring GRE, NAT, RIPSO, and BFE Servicesxviii308625-14.20 Rev 00Related PublicationsFor more information about GRE, NAT, and other IP services, r

Strona 92

308625-14.20 Rev 004-1 Chapter 4Connecting the Router to a Blacker Front EndThis chapter describes the Blacker front end (BFE) and provides instructio

Strona 93

Configuring GRE, NAT, RIPSO, and BFE Services4-2308625-14.20 Rev 00Blacker Front End (BFE) Concepts and TerminologyThe BFE is a classified encryption

Strona 94

Connecting the Router to a Blacker Front End308625-14.20 Rev 004-3 BFE devices receive authorization and address translation services from an access c

Strona 95

Configuring GRE, NAT, RIPSO, and BFE Services4-4308625-14.20 Rev 00BFE AddressingYou can enable BFE support on individual IP interfaces. Once enabled,

Strona 96

Connecting the Router to a Blacker Front End308625-14.20 Rev 004-5 Configuring BFE Support To configure BFE support on an IP interface, you must:• Con

Strona 97

Configuring GRE, NAT, RIPSO, and BFE Services4-6308625-14.20 Rev 00For instructions on performing steps 1 through 4, see Configuring X.25 Services. Fo

Strona 98 - Site Manager 2-56

Connecting the Router to a Blacker Front End308625-14.20 Rev 004-7 Outgoing SVC LCN Start Parameter is ignored.Number of PVC channels Zero (0). BFE do

Strona 99

Configuring GRE, NAT, RIPSO, and BFE Services4-8308625-14.20 Rev 00Full Addressing OnAcceptance Format DefextRelease Format DefextCCITT (now ITU-T) Co

Strona 100 - <ip_address>

Connecting the Router to a Blacker Front End308625-14.20 Rev 004-9 Packet Size Options include 128, 256, 512, and 1024. If you want to use a value oth

Strona 101

Preface308625-14.20 Rev 00xix • Configuring IP Exterior Gateway Protocols (BGP and EGP) (Nortel Networks part number 308628-14.00 Rev 00)Provides a de

Strona 103

308625-14.20 Rev 00A-1 Appendix ASite Manager ParametersThis appendix contains the Site Manager parameter descriptions for GRE, NAT, and RIPSO. You ca

Strona 104 - NAT router

Configuring GRE, NAT, RIPSO, and BFE ServicesA-2308625-14.20 Rev 00The Technician Interface allows you to modify parameters by issuing set and commit

Strona 105 - RIP, and OSPF Services

Site Manager Parameters308625-14.20 Rev 00A-3 To access the GRE Create Tunnels List window, complete the following tasks: Site Manager ProcedureYou do

Strona 106 - (continued)

Configuring GRE, NAT, RIPSO, and BFE ServicesA-4308625-14.20 Rev 00Remote Connection ParametersThe Create GRE Remote Connection window (Figure A-2) al

Strona 107 - (continued)

Site Manager Parameters308625-14.20 Rev 00A-5 To access the Create GRE Remote Connection window, complete the following tasks: Site Manager ProcedureY

Strona 108 - NAT Translation

Configuring GRE, NAT, RIPSO, and BFE ServicesA-6308625-14.20 Rev 00Parameter: Remote Physical IP AddressPath: Configuration Manager > Protocols >

Strona 109

Site Manager Parameters308625-14.20 Rev 00A-7 NAT ParametersNAT parameters are described in the following sections:NAT Global ParametersThe NAT Global

Strona 110

Configuring GRE, NAT, RIPSO, and BFE ServicesA-8308625-14.20 Rev 00Parameter: EnablePath: Configuration Manager > Protocols > IP > NAT > G

Strona 111

Site Manager Parameters308625-14.20 Rev 00A-9 Parameter: Log MaskPath: Configuration Manager > Protocols > IP > NAT > GlobalDefault: 0x000

Strona 112 - Where to Go Next

ii308625-14.20 Rev 00 Copyright © 2000 Nortel NetworksAll rights reserved. October 2000.The information in this document is subject to change without

Strona 114 - Using Site Manager

Configuring GRE, NAT, RIPSO, and BFE ServicesA-10308625-14.20 Rev 00Parameter: Mapping Timeout (secs)Path: Configuration Manager > Protocols > I

Strona 115

Site Manager Parameters308625-14.20 Rev 00A-11 NAT Interface ParametersThe NAT Interface List window allows access to NAT interface parameters. If you

Strona 116

Configuring GRE, NAT, RIPSO, and BFE ServicesA-12308625-14.20 Rev 00NAT Static Translation ParametersThe NAT Static Translation List window allows acc

Strona 117 - Logging NAT Messages

Site Manager Parameters308625-14.20 Rev 00A-13 Parameter: EnablePath: Configuration Manager > Protocols > IP > NAT > Static MappingDefault

Strona 118

Configuring GRE, NAT, RIPSO, and BFE ServicesA-14308625-14.20 Rev 00Parameter: Source DomainPath: Configuration Manager > Protocols > IP > NA

Strona 119

Site Manager Parameters308625-14.20 Rev 00A-15 Parameter: Destination DomainPath: Configuration Manager > Protocols > IP > NAT > Static Ma

Strona 120

Configuring GRE, NAT, RIPSO, and BFE ServicesA-16308625-14.20 Rev 00Adding Static Translation ParametersTo add static translations, whether bidirectio

Strona 121

Site Manager Parameters308625-14.20 Rev 00A-17 Depending on the type of configuration you want, go to the appropriate section:Adding NAT Bidirectional

Strona 122 - Customizing a NAT Interface

Configuring GRE, NAT, RIPSO, and BFE ServicesA-18308625-14.20 Rev 00Parameter: Source DomainPath: Configuration Manager > Protocols > IP > NA

Strona 123

Site Manager Parameters308625-14.20 Rev 00A-19 Parameter: Destination DomainPath: Configuration Manager > Protocols > IP > NAT > Static Ma

Strona 124

308625-14.20 Rev 001-1 Chapter 1Configuring GRE TunnelsThis chapter provides information about Generic Routing Encapsulation (GRE) tunnels and instruc

Strona 125

Configuring GRE, NAT, RIPSO, and BFE ServicesA-20308625-14.20 Rev 00Adding NAT SDPT ParametersTo configure NAT static destination port translation (SD

Strona 126

Site Manager Parameters308625-14.20 Rev 00A-21 Parameter: Private PortPath: Configuration Manager > Protocols > IP > NAT > Static Mapping

Strona 127

Configuring GRE, NAT, RIPSO, and BFE ServicesA-22308625-14.20 Rev 00Adding NAT Unidirectional ParametersTo configure static, unidirectional NAT, set t

Strona 128

Site Manager Parameters308625-14.20 Rev 00A-23 Parameter: Static NexthopPath: Configuration Manager > Protocols > IP > NAT > Static Mappin

Strona 129

Configuring GRE, NAT, RIPSO, and BFE ServicesA-24308625-14.20 Rev 00NAT Dynamic Mapping ParametersTo access the NAT dynamic mapping configuration wind

Strona 130

Site Manager Parameters308625-14.20 Rev 00A-25 NAT Source Address Filter ParametersThe following parameters are accessible from the NAT Source Address

Strona 131 - The results of the

Configuring GRE, NAT, RIPSO, and BFE ServicesA-26308625-14.20 Rev 00Parameter: Translation Pool SelectorPath: Configuration Manager > Protocols >

Strona 132 - in-domain-name

Site Manager Parameters308625-14.20 Rev 00A-27 Parameter: Static NexthopPath: Configuration Manager > Protocols > IP > NAT > Dynamic Mappi

Strona 133 - DNS proxy

Configuring GRE, NAT, RIPSO, and BFE ServicesA-28308625-14.20 Rev 00Adding Source Address Filter ParametersThe following parameters are accessible whe

Strona 134

Site Manager Parameters308625-14.20 Rev 00A-29 Parameter: Domain NamePath: Configuration Manager > Protocols > IP > NAT > Dynamic Mapping

Strona 135

Configuring GRE, NAT, RIPSO, and BFE Services1-2308625-14.20 Rev 00GRE Concepts and TerminologyGeneric Routing Encapsulation (GRE) is a protocol that

Strona 136

Configuring GRE, NAT, RIPSO, and BFE ServicesA-30308625-14.20 Rev 00Parameter: Nto1 AddressPath: Configuration Manager > Protocols > IP > NAT

Strona 137

Site Manager Parameters308625-14.20 Rev 00A-31 NAT Translation Pool ParametersThe following parameters are accessible from the NAT Translation Pool Li

Strona 138

Configuring GRE, NAT, RIPSO, and BFE ServicesA-32308625-14.20 Rev 00Adding NAT Translation Pool ParametersThe following parameters are accessible when

Strona 139

Site Manager Parameters308625-14.20 Rev 00A-33 Parameter: Prefix LengthPath: Configuration Manager > Protocols > IP > NAT > Dynamic Mappin

Strona 140

Configuring GRE, NAT, RIPSO, and BFE ServicesA-34308625-14.20 Rev 00RIPSO ParametersThe IP Interface List window (Figure A-3) allows access to paramet

Strona 141

Site Manager Parameters308625-14.20 Rev 00A-35 Parameter: Enable SecurityPath: Configuration Manager > Protocols > IP > InterfacesDefault: En

Strona 142

Configuring GRE, NAT, RIPSO, and BFE ServicesA-36308625-14.20 Rev 00Parameter: Require Out SecurityPath: Configuration Manager > Protocols > IP

Strona 143

Site Manager Parameters308625-14.20 Rev 00A-37 Parameter: Minimum LevelPath: Configuration Manager > Protocols > IP > InterfacesDefault: Uncl

Strona 144

Configuring GRE, NAT, RIPSO, and BFE ServicesA-38308625-14.20 Rev 00Parameter: Must Out AuthorityPath: Configuration Manager > Protocols > IP &g

Strona 145 - Site Manager 2-102

Site Manager Parameters308625-14.20 Rev 00A-39 Parameter: Must In AuthorityPath: Configuration Manager > Protocols > IP > InterfacesDefault:

Strona 146

Configuring GRE Tunnels308625-14.20 Rev 001-3 How GRE Tunneling WorksA simple point-to-point GRE tunnel terminates at router interfaces at each end of

Strona 147

Configuring GRE, NAT, RIPSO, and BFE ServicesA-40308625-14.20 Rev 00Parameter: Implicit LabelPath: Configuration Manager > Protocols > IP > I

Strona 148

Site Manager Parameters308625-14.20 Rev 00A-41 Parameter: Implicit LevelPath: Configuration Manager > Protocols > IP > InterfacesDefault: Unc

Strona 149

Configuring GRE, NAT, RIPSO, and BFE ServicesA-42308625-14.20 Rev 00Parameter: Default AuthorityPath: Configuration Manager > Protocols > IP >

Strona 150

Site Manager Parameters308625-14.20 Rev 00A-43 Parameter: Error LabelPath: Configuration Manager > Protocols > IP > InterfacesDefault: Enable

Strona 152

308625-14.20 Rev 00B-1 Appendix BSample Bidirectional NAT ConfigurationPROBLEM: Hosts in two domains at your site need to share information, yet you n

Strona 153

Configuring GRE, NAT, RIPSO, and BFE ServicesB-2308625-14.20 Rev 00The configuration tasks are similar when configuring static bidirectional NAT, exce

Strona 154 - Adding a Translation Pool

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-3 The address translation at the NAT router occurs with the assistance of BayRS DNS proxy o

Strona 155

Configuring GRE, NAT, RIPSO, and BFE ServicesB-4308625-14.20 Rev 001. Configure a DNS server with a public address on the same network as the router t

Strona 156

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-5 Configuring RIP2 on the router IP interface 25.2.2.2 for domain1:ip/25.2.2.2/255.0.0.0# r

Strona 157

Configuring GRE, NAT, RIPSO, and BFE Services1-4308625-14.20 Rev 00The GRE tunnel can use any IP interface configured on the router as a physical end

Strona 158

Configuring GRE, NAT, RIPSO, and BFE ServicesB-6308625-14.20 Rev 00fwd-port 53fwd-server1-address 99.9.9.9fwd-server2-address 0.0.0.0fwd-server3-addre

Strona 159 - Deleting a Translation Pool

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-7 To view the status of the NAT interfaces on the router, enter the show nat interfaces com

Strona 160

Configuring GRE, NAT, RIPSO, and BFE ServicesB-8308625-14.20 Rev 00To check the addresses in a source address filter and to see whether a source addre

Strona 161

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-9 8.Configure DNS client on each device in the domains that will initiate IP traffic whose

Strona 162

Configuring GRE, NAT, RIPSO, and BFE ServicesB-10308625-14.20 Rev 00Checking Address TranslationsAfter you configure your router for bidirectional NAT

Strona 163 - Chapter 3

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-11 show nat domains (BCC)The command show nat domains displays address translations for the

Strona 164

Configuring GRE, NAT, RIPSO, and BFE ServicesB-12308625-14.20 Rev 00• The fourth translation is for host B (4.1.1.1) in the inbound domain (domain2.ne

Strona 165 - Security Label Format

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-13 • The output columns IP Protocol (UDP, TCP, or none are possible values), Original Port,

Strona 166 - Inbound IP Datagrams

Configuring GRE, NAT, RIPSO, and BFE ServicesB-14308625-14.20 Rev 00The output columns Original Port and Translated Port display port number informati

Strona 167 - Unlabeled IP Datagrams

308625-14.20 Rev 00Index-1Aaccept policies, configuring for GRE tunnels, 1-7, 1-8acronyms, xviiaddress translation precedence (NAT), 2-35aging (NAT),

Strona 168 - Enabling and Disabling RIPSO

Configuring GRE Tunnels308625-14.20 Rev 001-5 Figure 1-2. GRE Tunnel Encapsulating the IP ProtocolGRE Packet HeadersThe previous example followed the

Strona 169

Index-2308625-14.20 Rev 00delete command (BCC)GREremote tunnel end point, 1-26tunnel, 1-27tunnel protocol, 1-24NATfrom a router interface, 2-79source

Strona 170

308625-14.20 Rev 00Index-3EECMP support limitation for NAT, 2-33Enable parameterGREremote tunnel end point, 1-26, A-5tunnel, 1-22, A-4NATglobal, 2-66,

Strona 171

Index-4308625-14.20 Rev 00LL1 Default Metric parameter (OSI), 1-15L1 Designated Router Priority parameter (OSI), 1-15L2 Default Metric parameter (OSI)

Strona 172

308625-14.20 Rev 00Index-5NAT (continued)dynamic translations (continued)reenabling a source address filter, 2-103reenabling a translation pool, 2-109

Strona 173

Index-6308625-14.20 Rev 00NAT (continued)translation pool (continued)disabling, 2-109enabling, 2-109more than one in a domain, 2-11pairing with source

Strona 174

308625-14.20 Rev 00Index-7publicationshard copy, xixrelated, xviiiRRedirect Enable/Disable parameter (OSI), 1-15reenablingGREremote tunnel end point,

Strona 175

Index-8308625-14.20 Rev 00security classification (RIPSO), 3-4security labels (RIPSO)format, 3-3specifying inbound datagram types that require, 3-9spe

Strona 176 - Outbound Datagrams

308625-14.20 Rev 00Index-9timeout (NAT)aging, enabling/disabling, 2-71value, configuring for dynamic translations, 2-72timeout command (BCC), 2-71time

Strona 178 - RIPSO Example

Configuring GRE, NAT, RIPSO, and BFE Services1-6308625-14.20 Rev 00Figure 1-3. GRE Packet HeadersThe outermost (delivery) header is an IP header with

Strona 179 - Figure 3-2. RIPSO Example

Configuring GRE Tunnels308625-14.20 Rev 001-7 Requirements for GRE Tunnels Encapsulating IP ProtocolBefore configuring a tunnel encapsulating IP, you

Strona 180

Configuring GRE, NAT, RIPSO, and BFE Services1-8308625-14.20 Rev 00The disadvantage of using an announce policy is that it prevents the advertisement

Strona 181 - Chapter 4

Configuring GRE Tunnels308625-14.20 Rev 001-9 Number of Tunnels Configurable per RouterThe number of GRE tunnels you can configure on a router varies,

Strona 182

308625-14.20 Rev 00iiiNortel Networks NA Inc. Software License AgreementNOTICE: Please carefully read this license agreement before copying or using t

Strona 183

Configuring GRE, NAT, RIPSO, and BFE Services1-10308625-14.20 Rev 00Creating a GRE TunnelTo create a tunnel:1. Configure the local tunnel end point.2.

Strona 184 - BFE Addressing

Configuring GRE Tunnels308625-14.20 Rev 001-11 name is a unique name for this tunnel.address is a valid IP address of a local router interface express

Strona 185 - Configuring BFE Support

Configuring GRE, NAT, RIPSO, and BFE Services1-12308625-14.20 Rev 00Adding a Protocol to the Local Tunnel End PointThe Nortel Networks implementation

Strona 186

Configuring GRE Tunnels308625-14.20 Rev 001-13 Adding an IPX Protocol InterfaceTo add an IPX protocol interface to the local tunnel end point, navigat

Strona 187

Configuring GRE, NAT, RIPSO, and BFE Services1-14308625-14.20 Rev 00Adding an OSI Protocol InterfaceTo add the OSI protocol to the local tunnel end po

Strona 188

Configuring GRE Tunnels308625-14.20 Rev 001-15 6. Set the following parameters (required if OSI has not been configured previously on any other router

Strona 189

Configuring GRE, NAT, RIPSO, and BFE Services1-16308625-14.20 Rev 00Configuring the Remote Tunnel End PointA remote tunnel end point can be any IP int

Strona 190

Configuring GRE Tunnels308625-14.20 Rev 001-17 Using the BCCTo configure a remote tunnel end point using the BCC, complete the following steps.Step 1.

Strona 191 - Site Manager Parameters

Configuring GRE, NAT, RIPSO, and BFE Services1-18308625-14.20 Rev 00Configuring a Remote Logical IP InterfaceTo configure a remote logical IP interfac

Strona 192 - GRE Parameters

Configuring GRE Tunnels308625-14.20 Rev 001-19 Using Site ManagerConfiguring a Remote End Point for IP or IPXTo configure a remote tunnel end point fo

Strona 193

iv308625-14.20 Rev 00for the security of its own data and information and for maintaining adequate procedures apart from the Software to reconstruct

Strona 194 - Remote Connection Parameters

Configuring GRE, NAT, RIPSO, and BFE Services1-20308625-14.20 Rev 00Configuring a Remote End Point for OSITo configure a remote tunnel end point for t

Strona 195

Configuring GRE Tunnels308625-14.20 Rev 001-21 Customizing a GRE TunnelYou can customize a configured GRE tunnel, as described in the following sectio

Strona 196

Configuring GRE, NAT, RIPSO, and BFE Services1-22308625-14.20 Rev 00Using Site ManagerTo disable or reenable a GRE tunnel, complete the following task

Strona 197 - NAT Parameters

Configuring GRE Tunnels308625-14.20 Rev 001-23 For example, the following command disables the IP protocol interface 9.9.9.1/255.255.255.0:ip/9.9.9.1/

Strona 198 - Caution:

Configuring GRE, NAT, RIPSO, and BFE Services1-24308625-14.20 Rev 00Deleting a Protocol from a GRE TunnelUse the BCC or Site Manager to delete a proto

Strona 199

Configuring GRE Tunnels308625-14.20 Rev 001-25 Disabling and Reenabling a Remote Tunnel End PointWhen you configure a remote tunnel end point, it is e

Strona 200

Configuring GRE, NAT, RIPSO, and BFE Services1-26308625-14.20 Rev 00Using Site ManagerTo disable or reenable a remote tunnel end point, complete the f

Strona 201 - NAT Interface Parameters

Configuring GRE Tunnels308625-14.20 Rev 001-27 Using Site ManagerTo delete a remote tunnel end point, complete the following tasks:Deleting a GRE Tunn

Strona 202

Configuring GRE, NAT, RIPSO, and BFE Services1-28308625-14.20 Rev 00Using Site ManagerTo delete a GRE tunnel, complete the following tasks: Site Manag

Strona 203

308625-14.20 Rev 002-1Chapter 2Configuring Network Address TranslationThis chapter describes network address translation (NAT) and provides instructio

Strona 204

308625-14.20 Rev 00vContents PrefaceText Conventions ...

Strona 205

Configuring GRE, NAT, RIPSO, and BFE Services2-2308625-14.20 Rev 00NAT ConceptsNetwork Address Translation is a method by which IP addresses are mappe

Strona 206

Configuring Network Address Translation308625-14.20 Rev 002-3Unidirectional NATFor unidirectional NAT, the translation is done for addresses within th

Strona 207

Configuring GRE, NAT, RIPSO, and BFE Services2-4308625-14.20 Rev 00RequirementsIn addition to configuring NAT on the router, unidirectional NAT (inclu

Strona 208

Configuring Network Address Translation308625-14.20 Rev 002-5Representing Multiple Hosts with a Single Address: SDPT and N-to-1For TCP and UDP traffic

Strona 209

Configuring GRE, NAT, RIPSO, and BFE Services2-6308625-14.20 Rev 00The major difference between SDPT and N-to-1 translation is that N-to-1 applies onl

Strona 210 - Adding NAT SDPT Parameters

Configuring Network Address Translation308625-14.20 Rev 002-7Bidirectional (Multidomain) NATBidirectional multidomain NAT is a unique feature of BayRS

Strona 211

Configuring GRE, NAT, RIPSO, and BFE Services2-8308625-14.20 Rev 00• Install Domain Name System (DNS) server on a machine with a public interface to t

Strona 212

Configuring Network Address Translation308625-14.20 Rev 002-9The DNS proxy server accepts DNS name service requests from hosts on either side of the r

Strona 213

Configuring GRE, NAT, RIPSO, and BFE Services2-10308625-14.20 Rev 00Translation ModesYou can configure your router so that network address translation

Strona 214

Configuring Network Address Translation308625-14.20 Rev 002-11Dynamic Translation ModeNAT dynamic translation mode allows you to configure a temporary

Strona 215

vi308625-14.20 Rev 00Using the BCC ...1-17Step 1

Strona 216

Configuring GRE, NAT, RIPSO, and BFE Services2-12308625-14.20 Rev 00Comparing unidirectional and bidirectional dynamic NAT You can configure unidirect

Strona 217

Configuring Network Address Translation308625-14.20 Rev 002-13For instructions on how to configure mapping aging, see:• “Enabling and Disabling the Dy

Strona 218

Configuring GRE, NAT, RIPSO, and BFE Services2-14308625-14.20 Rev 00Unidirectional NATYou can configure the following types of unidirectional NAT: sta

Strona 219

Configuring Network Address Translation308625-14.20 Rev 002-15Dynamic Unidirectional Address TranslationNAT routers translate host addresses from insi

Strona 220

Configuring GRE, NAT, RIPSO, and BFE Services2-16308625-14.20 Rev 00Figure 2-2. Network Address Translation ExampleBostonAtlantaNew YorkSanta ClaraLon

Strona 221

Configuring Network Address Translation308625-14.20 Rev 002-17When the router’s NAT interface receives a packet, the NAT router extracts the source ad

Strona 222

Configuring GRE, NAT, RIPSO, and BFE Services2-18308625-14.20 Rev 00In Figure 2-4, the NAT router dynamically translates the source address, 10.0.0.15

Strona 223

Configuring Network Address Translation308625-14.20 Rev 002-19In Figure 2-5, the NAT router then replaces the private source address (10.0.0.15) with

Strona 224 - RIPSO Parameters

Configuring GRE, NAT, RIPSO, and BFE Services2-20308625-14.20 Rev 00The destination host uses the incoming packet’s source address to create a destina

Strona 225

Configuring Network Address Translation308625-14.20 Rev 002-21Figure 2-6. Sample Configuration for NAT SDPTThe HTTP server actually has a local IP add

Strona 226

308625-14.20 Rev 00viiStatic Destination and Port Translation (SDPT) ...2-20Network Address Port Translat

Strona 227

Configuring GRE, NAT, RIPSO, and BFE Services2-22308625-14.20 Rev 00It might seem as if this HTTP server has two identities: The server has its actual

Strona 228

Configuring Network Address Translation308625-14.20 Rev 002-23When TCP packets with a destination address of 192.32.29.17 arrive in the NAT-configured

Strona 229

Configuring GRE, NAT, RIPSO, and BFE Services2-24308625-14.20 Rev 00Figure 2-7. N-to-1 Translation (Part 1)The following events occur:1. NAT receives

Strona 230

Configuring Network Address Translation308625-14.20 Rev 002-252. NAT uses the address and the port number to identify the destination host.3. NAT repl

Strona 231

Configuring GRE, NAT, RIPSO, and BFE Services2-26308625-14.20 Rev 00Bidirectional NATYou can configure bidirectional NAT statically or dynamically, an

Strona 232

Configuring Network Address Translation308625-14.20 Rev 002-27When host A transmits packets to the NAT router, NAT replaces the source address in the

Strona 233

Configuring GRE, NAT, RIPSO, and BFE Services2-28308625-14.20 Rev 00Dynamic Bidirectional Address Translation with Two DomainsFigure 2-10 offers an ex

Strona 234

Configuring Network Address Translation308625-14.20 Rev 002-29A source address filter and translation pool are configured in each domain. Host A in do

Strona 235 - Appendix B

Configuring GRE, NAT, RIPSO, and BFE Services2-30308625-14.20 Rev 00Host A in domain 1 receives the DNS response message and saves the translation IP

Strona 236 - Sample Scenario

Configuring Network Address Translation308625-14.20 Rev 002-31Host B receives packets from and sends replies back to host A. The reply packets will ha

Strona 237

viii308625-14.20 Rev 00Customizing a NAT Interface ...2-74Addin

Strona 238

Configuring GRE, NAT, RIPSO, and BFE Services2-32308625-14.20 Rev 00NAT Implementation GuidelinesBefore you implement a NAT configuration, you should

Strona 239

Configuring Network Address Translation308625-14.20 Rev 002-33Protocol Requirements and CompatibilitiesConsider the following guidelines related to pr

Strona 240

Configuring GRE, NAT, RIPSO, and BFE Services2-34308625-14.20 Rev 00Compatibility of NAT and IPsec on a Router InterfaceYou can configure both unidire

Strona 241

Configuring Network Address Translation308625-14.20 Rev 002-35However, NAT SDPT support requires that you combine several translation types in your co

Strona 242

Configuring GRE, NAT, RIPSO, and BFE Services2-36308625-14.20 Rev 00When N-to-1 dynamic port translation is enabled, the source address (private inter

Strona 243

Configuring Network Address Translation308625-14.20 Rev 002-37Figure 2-14 illustrates a NAT configuration in which a dynamic address range encloses an

Strona 244 - Checking Address Translations

Configuring GRE, NAT, RIPSO, and BFE Services2-38308625-14.20 Rev 00Figure 2-15 illustrates configured NAT ranges that do not overlap. Packets with a

Strona 245 - <IP_address>

Configuring Network Address Translation308625-14.20 Rev 002-39Internet Control Message Protocol and Message HandlingNAT automatically allows Internet

Strona 246

Configuring GRE, NAT, RIPSO, and BFE Services2-40308625-14.20 Rev 00Starting NAT Services and Configuring TranslationsThis section provides instructio

Strona 247

Configuring Network Address Translation308625-14.20 Rev 002-41Step 1. Add NAT to a router interfaceTo configure NAT on a router interface, navigate to

Strona 248

308625-14.20 Rev 00ixSpecifying the Outbound Datagram Type Requiring Security Labels ...3-8Specifying the Inbound Datagram T

Strona 249

Configuring GRE, NAT, RIPSO, and BFE Services2-42308625-14.20 Rev 00prefix_length specifies the end of the IP address range available for translation.

Strona 250

Configuring Network Address Translation308625-14.20 Rev 002-43When configuring unidirectional NAT, you must use the special domain name “public” to id

Strona 251

Configuring GRE, NAT, RIPSO, and BFE Services2-44308625-14.20 Rev 00The info command lets you see the values configured so far for this source address

Strona 252

Configuring Network Address Translation308625-14.20 Rev 002-45Using Site ManagerBefore you can start NAT on the router, you must configure a circuit t

Strona 253

Configuring GRE, NAT, RIPSO, and BFE Services2-46308625-14.20 Rev 00Step 2. Configure the NAT public interfaceFor unidirectional NAT, the public inter

Strona 254

Configuring Network Address Translation308625-14.20 Rev 002-47Step 3. Configuring a source address filterFor unidirectional NAT, the source address fi

Strona 255

Configuring GRE, NAT, RIPSO, and BFE Services2-48308625-14.20 Rev 00Step 4. Configuring a translation poolThe translation pool specifies to the router

Strona 256

Configuring Network Address Translation308625-14.20 Rev 002-497. Set the following parameters:• IP Address• Prefix Length• Domain NameClick on Help or

Strona 257

Configuring GRE, NAT, RIPSO, and BFE Services2-50308625-14.20 Rev 00Configuring Bidirectional NAT (Dynamic)In the following bidirectional multidomain

Strona 258

Configuring Network Address Translation308625-14.20 Rev 002-51Step 1. Install DNS server on a device with a public interface to the NAT routerYou must

Komentarze do niniejszej Instrukcji

Brak uwag