Avaya Configuring BFE Services Bedienungsanleitung

Stöbern Sie online oder laden Sie Bedienungsanleitung nach Nein Avaya Configuring BFE Services herunter. Avaya Configuring BFE Services User's Manual Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 258
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - Configuring GRE, NAT, RIPSO

BayRS Version 14.20Part No. 308625-14.20 Rev 00October 2000600 Technology Park DriveBillerica, MA 01821-4130Configuring GRE, NAT, RIPSO, and BFE Serv

Seite 2 - Statement of Conditions

x308625-14.20 Rev 00Configuring Sample Bidirectional NAT Using the BCC ... B-3Information Used in Bid

Seite 3

Configuring GRE, NAT, RIPSO, and BFE Services2-52308625-14.20 Rev 00Step 4. Configure a NAT router interface to a device in each domain that will use

Seite 4

Configuring Network Address Translation308625-14.20 Rev 002-53For example, the following command sets the name-server parameter to IP address 192.32.7

Seite 5 - Contents

Configuring GRE, NAT, RIPSO, and BFE Services2-54308625-14.20 Rev 00Here is a look at what has been configured for DNS proxy, accepting default values

Seite 6

Configuring Network Address Translation308625-14.20 Rev 002-55unnumbered-circuit-name {}use-translation-pool outboundThe type parameter is a read-only

Seite 7

Configuring GRE, NAT, RIPSO, and BFE Services2-56308625-14.20 Rev 00Using Site ManagerTo use Site Manager to configure a dynamic bidirectional network

Seite 8

Configuring Network Address Translation308625-14.20 Rev 002-57Install DNS server on a device that has a public address connection to the router that w

Seite 9

Configuring GRE, NAT, RIPSO, and BFE Services2-58308625-14.20 Rev 00Step 4. Configure RIP2 on the router IP interfaces and on each device that will us

Seite 10 - 308625-14.20 Rev 00

Configuring Network Address Translation308625-14.20 Rev 002-59Steps 5, 6, 7: Configure NAT on an interface, specify a domain name, and identify a DNS

Seite 11

Configuring GRE, NAT, RIPSO, and BFE Services2-60308625-14.20 Rev 00* If, for some reason, you decide not to configure DNS proxy at this point, see th

Seite 12

Configuring Network Address Translation308625-14.20 Rev 002-61To configure a source address filter, complete the following tasks:Step 9. Configuring a

Seite 13

308625-14.20 Rev 00 xiFiguresFigure 1-1. Simple GRE Tunnel Components ...1-3Figure 1-2. GRE

Seite 14

Configuring GRE, NAT, RIPSO, and BFE Services2-62308625-14.20 Rev 00To configure a translation pool, complete the following tasks:Site Manager Procedu

Seite 15

Configuring Network Address Translation308625-14.20 Rev 002-63Step 10. Configure DNS client on each device in the domains that will initiate address t

Seite 16 - Text Conventions

Configuring GRE, NAT, RIPSO, and BFE Services2-64308625-14.20 Rev 00Where to Go NextThe instructions in “Starting NAT Services and Configuring Transla

Seite 17 - Acronyms

Configuring Network Address Translation308625-14.20 Rev 002-65Customizing NAT Global ParametersTo customize the way NAT operates on a router, modify N

Seite 18 - Related Publications

Configuring GRE, NAT, RIPSO, and BFE Services2-66308625-14.20 Rev 00Enabling and Disabling NAT on the RouterWhen you first configure any router interf

Seite 19 - How to Get Help

Configuring Network Address Translation308625-14.20 Rev 002-67Configuring the Soloist Slot MaskBy default, the router uses any available slot for the

Seite 20

Configuring GRE, NAT, RIPSO, and BFE Services2-68308625-14.20 Rev 00Using Site ManagerTo specify the slots on which NAT can run as a soloist, complete

Seite 21 - Configuring GRE Tunnels

Configuring Network Address Translation308625-14.20 Rev 002-69Logging NAT MessagesBy default, BayRS does not log NAT messages. You can enable the logg

Seite 22 - GRE Concepts and Terminology

Configuring GRE, NAT, RIPSO, and BFE Services2-70308625-14.20 Rev 00Using Site ManagerTo specify the types of log messages that are reported by NAT so

Seite 23 - How GRE Tunneling Works

Configuring Network Address Translation308625-14.20 Rev 002-71Enabling and Disabling the Dynamic Mapping Aging TimerBy default, the router deletes exp

Seite 25

Configuring GRE, NAT, RIPSO, and BFE Services2-72308625-14.20 Rev 00Configuring the Dynamic Mapping Timeout ValueA NAT dynamic mapping (translation en

Seite 26 - Checksum (optional)

Configuring Network Address Translation308625-14.20 Rev 002-73Using the BCCTo configure the timeout period for a dynamic translation entry, navigate t

Seite 27

Configuring GRE, NAT, RIPSO, and BFE Services2-74308625-14.20 Rev 00Customizing a NAT InterfaceThis section includes the following topics:Adding NAT t

Seite 28

Configuring Network Address Translation308625-14.20 Rev 002-75Using Site ManagerTo add NAT to a router IP interface, complete the following tasks:Site

Seite 29

Configuring GRE, NAT, RIPSO, and BFE Services2-76308625-14.20 Rev 008. Click on Yes or click on No:• If you click on Yes, specify an address for DNS S

Seite 30 - Creating a GRE Tunnel

Configuring Network Address Translation308625-14.20 Rev 002-77Disabling and Reenabling NAT on an InterfaceWhen you add NAT to a router interface, NAT

Seite 31

Configuring GRE, NAT, RIPSO, and BFE Services2-78308625-14.20 Rev 00Using Site ManagerTo disable or reenable NAT on an interface, complete the followi

Seite 32

Configuring Network Address Translation308625-14.20 Rev 002-79Deleting NAT from an InterfaceWhen you delete NAT from the last NAT-configured interface

Seite 33

Configuring GRE, NAT, RIPSO, and BFE Services2-80308625-14.20 Rev 00Configuring NAT Static Address TranslationStatic address mapping entries must be u

Seite 34

Configuring Network Address Translation308625-14.20 Rev 002-81Adding a Static Unidirectional Address MappingTo add a static unidirectional mapping, yo

Seite 35

308625-14.20 Rev 00xiiiTablesTable 2-1. Comparing NAT Types SDPT and N-to-1 ...2-5Table 2-2. Sample Conf

Seite 36

Configuring GRE, NAT, RIPSO, and BFE Services2-82308625-14.20 Rev 00Optionally, you can specify either a static next hop or an unnumbered circuit name

Seite 37

Configuring Network Address Translation308625-14.20 Rev 002-83out-domain-name publicstate enabledtranslated-address 199.1.42.200unnumbered-circuit-nam

Seite 38 - <address>

Configuring GRE, NAT, RIPSO, and BFE Services2-84308625-14.20 Rev 00Adding a Static Bidirectional Address MappingFor static bidirectional NAT, you mus

Seite 39

Configuring Network Address Translation308625-14.20 Rev 002-85Similar to static unidirectional mapping, you are mapping a single address to another si

Seite 40

Configuring GRE, NAT, RIPSO, and BFE Services2-86308625-14.20 Rev 00Using the BCCTo add a bidirectional static address mapping on the NAT router, navi

Seite 41 - Customizing a GRE Tunnel

Configuring Network Address Translation308625-14.20 Rev 002-87Examples of Configuring Static Bidirectional NAT to Work with or Independent of DNS Prox

Seite 42

Configuring GRE, NAT, RIPSO, and BFE Services2-88308625-14.20 Rev 004. Choose Static Mapping. The NAT Static Translation List window opens.5. Click on

Seite 43 - 9.9.9.1/255.255.255.0:

Configuring Network Address Translation308625-14.20 Rev 002-89Adding an SDPT Address and Port MappingTo configure NAT SDPT you statically map the addr

Seite 44

Configuring GRE, NAT, RIPSO, and BFE Services2-90308625-14.20 Rev 00translated_address is the public address that you want to map to the original addr

Seite 45

Configuring Network Address Translation308625-14.20 Rev 002-91ip/192.1.2.3/255.0.0.0# nat domain-name publicnat/192.1.2.3#Using Site ManagerBefore you

Seite 47 - Deleting a GRE Tunnel

Configuring GRE, NAT, RIPSO, and BFE Services2-92308625-14.20 Rev 00Disabling and Reenabling a Static Address MappingWhen you add a NAT static address

Seite 48

Configuring Network Address Translation308625-14.20 Rev 002-93Using Site ManagerTo disable or reenable a static address mapping, complete the followin

Seite 49 - Chapter 2

Configuring GRE, NAT, RIPSO, and BFE Services2-94308625-14.20 Rev 00Using Site ManagerTo delete a static address mapping, complete the following tasks

Seite 50 - NAT Concepts

Configuring Network Address Translation308625-14.20 Rev 002-95Configuring NAT Dynamic Address TranslationFor dynamic NAT to work, you must do the foll

Seite 51 - Unidirectional NAT

Configuring GRE, NAT, RIPSO, and BFE Services2-96308625-14.20 Rev 005. Configure a range of addresses as a translation pool. Instructions follow. Dyna

Seite 52 - For this information See

Configuring Network Address Translation308625-14.20 Rev 002-97Adding a Source Address FilterA source address filter is a range of addresses within a d

Seite 53

Configuring GRE, NAT, RIPSO, and BFE Services2-98308625-14.20 Rev 00IP Address and Prefix Length ParameterTo identify an address range for a source ad

Seite 54

Configuring Network Address Translation308625-14.20 Rev 002-99Use the BCC parameter use-translation-pool or the Site Manager parameter Translation Poo

Seite 55

Configuring GRE, NAT, RIPSO, and BFE Services2-100308625-14.20 Rev 00Using the BCCTo configure a source address filter, navigate to the domain name pr

Seite 56

Configuring Network Address Translation308625-14.20 Rev 002-101Examples of specifying a translation pool for a source address filterIf you configure a

Seite 57

308625-14.20 Rev 00xv PrefaceThis guide describes the following services and what you do to start and customize them on a Nortel Networks™ router:• Ge

Seite 58 - Translation Modes

Configuring GRE, NAT, RIPSO, and BFE Services2-102308625-14.20 Rev 00Using Site ManagerTo configure a source address filter, complete the following ta

Seite 59

Configuring Network Address Translation308625-14.20 Rev 002-103Disabling and Reenabling a Source Address FilterWhen you add a source address filter, i

Seite 60

Configuring GRE, NAT, RIPSO, and BFE Services2-104308625-14.20 Rev 00Using Site ManagerTo disable or reenable a source address filter, complete the fo

Seite 61 - show ip

Configuring Network Address Translation308625-14.20 Rev 002-105Deleting a Source Address FilterUse the BCC or Site Manager to delete a source address

Seite 62

Configuring GRE, NAT, RIPSO, and BFE Services2-106308625-14.20 Rev 00Adding a Translation PoolA translation pool is a range of IP addresses that you s

Seite 63

Configuring Network Address Translation308625-14.20 Rev 002-107Using the BCCTo configure a translation pool, navigate to the domain name prompt (for e

Seite 64

Configuring GRE, NAT, RIPSO, and BFE Services2-108308625-14.20 Rev 007. Set the following parameters:• IP Address• Prefix Length• Domain NameClick on

Seite 65

Configuring Network Address Translation308625-14.20 Rev 002-109Disabling and Reenabling a Translation PoolWhen you create a translation pool, it is en

Seite 66

Configuring GRE, NAT, RIPSO, and BFE Services2-110308625-14.20 Rev 00Using Site ManagerTo disable or reenable a translation pool, complete the followi

Seite 67

Configuring Network Address Translation308625-14.20 Rev 002-111Deleting a Translation PoolUse the BCC or Site Manager to delete a translation pool.Usi

Seite 68

Configuring GRE, NAT, RIPSO, and BFE Servicesxvi308625-14.20 Rev 00Text ConventionsThis guide uses the following text conventions:angle brackets (<

Seite 69

Configuring GRE, NAT, RIPSO, and BFE Services2-112308625-14.20 Rev 006. Select the translation pool that you want to delete from the list in the upper

Seite 70

Configuring Network Address Translation308625-14.20 Rev 002-113Configuring NAT N-to-1 TranslationNAT N-to-1 translation allows you to configure a rang

Seite 71

Configuring GRE, NAT, RIPSO, and BFE Services2-114308625-14.20 Rev 00For example, the following command sequence configures the IP address 199.1.42.10

Seite 72

308625-14.20 Rev 003-1 Chapter 3Configuring RIPSO on an IP InterfaceThis chapter describes RIPSO and provides instructions for configuring RIPSO on an

Seite 73

Configuring GRE, NAT, RIPSO, and BFE Services3-2308625-14.20 Rev 00RIPSO Concepts and TerminologyIP routers support the Department of Defense (DoD) Re

Seite 74 - Bidirectional NAT

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-3 You also specify whether the router creates the following types of labels:• An implicit lab

Seite 75

Configuring GRE, NAT, RIPSO, and BFE Services3-4308625-14.20 Rev 00• Octet 4 and beyond identify the protection authorities under whose rules the data

Seite 76 - Domain 2

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-5 • The authority flags in the datagram’s label must include all flags required for the inter

Seite 77

Configuring GRE, NAT, RIPSO, and BFE Services3-6308625-14.20 Rev 00• If the inbound interface does not have an implicit label configured, the router l

Seite 78 - Domain 3

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-7 Specifying the IP Datagram Type for Stripping Security OptionsUse Site Manager to choose th

Seite 79

Preface308625-14.20 Rev 00xvii AcronymsThis guide uses the following acronyms::screen text Indicates system output, for example, prompts and system me

Seite 80 - NAT Implementation Guidelines

Configuring GRE, NAT, RIPSO, and BFE Services3-8308625-14.20 Rev 00Specifying the Outbound Datagram Type Requiring Security LabelsUse Site Manager to

Seite 81

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-9 Specifying the Inbound Datagram Type Requiring Security LabelsUse Site Manager to specify t

Seite 82

Configuring GRE, NAT, RIPSO, and BFE Services3-10308625-14.20 Rev 00Setting the Security Level for IP DatagramsUse Site Manager to specify the minimum

Seite 83

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-11 Choosing Authority Flags in Outbound DatagramsUse Site Manager to specify which authority

Seite 84

Configuring GRE, NAT, RIPSO, and BFE Services3-12308625-14.20 Rev 00Choosing Authority Flags in Inbound DatagramsUse Site Manager to specify which aut

Seite 85

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-13 Supplying Implicit Labels for Unlabeled Inbound DatagramsUse Site Manager to specify wheth

Seite 86

Configuring GRE, NAT, RIPSO, and BFE Services3-14308625-14.20 Rev 00Enabling and Disabling Default Labels for Unlabeled Outbound DatagramsUse Site Man

Seite 87

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-15 Enabling and Disabling Error Labels for Outbound ICMP Error DatagramsUse Site Manager to s

Seite 88 - Site Manager 2-45

Configuring GRE, NAT, RIPSO, and BFE Services3-16308625-14.20 Rev 00RIPSO ExampleThe router in Figure 3-2 has RIPSO configured on all three IP interfa

Seite 89

Configuring RIPSO on an IP Interface308625-14.20 Rev 003-17 Figure 3-2. RIPSO Example1.1.0.11.1.0.21.2.0.1 1.3.0.11.1.0.1Forward outbounddatagram?

Seite 90

Configuring GRE, NAT, RIPSO, and BFE Servicesxviii308625-14.20 Rev 00Related PublicationsFor more information about GRE, NAT, and other IP services, r

Seite 92

308625-14.20 Rev 004-1 Chapter 4Connecting the Router to a Blacker Front EndThis chapter describes the Blacker front end (BFE) and provides instructio

Seite 93

Configuring GRE, NAT, RIPSO, and BFE Services4-2308625-14.20 Rev 00Blacker Front End (BFE) Concepts and TerminologyThe BFE is a classified encryption

Seite 94

Connecting the Router to a Blacker Front End308625-14.20 Rev 004-3 BFE devices receive authorization and address translation services from an access c

Seite 95

Configuring GRE, NAT, RIPSO, and BFE Services4-4308625-14.20 Rev 00BFE AddressingYou can enable BFE support on individual IP interfaces. Once enabled,

Seite 96

Connecting the Router to a Blacker Front End308625-14.20 Rev 004-5 Configuring BFE Support To configure BFE support on an IP interface, you must:• Con

Seite 97

Configuring GRE, NAT, RIPSO, and BFE Services4-6308625-14.20 Rev 00For instructions on performing steps 1 through 4, see Configuring X.25 Services. Fo

Seite 98 - Site Manager 2-56

Connecting the Router to a Blacker Front End308625-14.20 Rev 004-7 Outgoing SVC LCN Start Parameter is ignored.Number of PVC channels Zero (0). BFE do

Seite 99

Configuring GRE, NAT, RIPSO, and BFE Services4-8308625-14.20 Rev 00Full Addressing OnAcceptance Format DefextRelease Format DefextCCITT (now ITU-T) Co

Seite 100 - <ip_address>

Connecting the Router to a Blacker Front End308625-14.20 Rev 004-9 Packet Size Options include 128, 256, 512, and 1024. If you want to use a value oth

Seite 101

Preface308625-14.20 Rev 00xix • Configuring IP Exterior Gateway Protocols (BGP and EGP) (Nortel Networks part number 308628-14.00 Rev 00)Provides a de

Seite 103

308625-14.20 Rev 00A-1 Appendix ASite Manager ParametersThis appendix contains the Site Manager parameter descriptions for GRE, NAT, and RIPSO. You ca

Seite 104 - NAT router

Configuring GRE, NAT, RIPSO, and BFE ServicesA-2308625-14.20 Rev 00The Technician Interface allows you to modify parameters by issuing set and commit

Seite 105 - RIP, and OSPF Services

Site Manager Parameters308625-14.20 Rev 00A-3 To access the GRE Create Tunnels List window, complete the following tasks: Site Manager ProcedureYou do

Seite 106 - (continued)

Configuring GRE, NAT, RIPSO, and BFE ServicesA-4308625-14.20 Rev 00Remote Connection ParametersThe Create GRE Remote Connection window (Figure A-2) al

Seite 107 - (continued)

Site Manager Parameters308625-14.20 Rev 00A-5 To access the Create GRE Remote Connection window, complete the following tasks: Site Manager ProcedureY

Seite 108 - NAT Translation

Configuring GRE, NAT, RIPSO, and BFE ServicesA-6308625-14.20 Rev 00Parameter: Remote Physical IP AddressPath: Configuration Manager > Protocols >

Seite 109

Site Manager Parameters308625-14.20 Rev 00A-7 NAT ParametersNAT parameters are described in the following sections:NAT Global ParametersThe NAT Global

Seite 110

Configuring GRE, NAT, RIPSO, and BFE ServicesA-8308625-14.20 Rev 00Parameter: EnablePath: Configuration Manager > Protocols > IP > NAT > G

Seite 111

Site Manager Parameters308625-14.20 Rev 00A-9 Parameter: Log MaskPath: Configuration Manager > Protocols > IP > NAT > GlobalDefault: 0x000

Seite 112 - Where to Go Next

ii308625-14.20 Rev 00 Copyright © 2000 Nortel NetworksAll rights reserved. October 2000.The information in this document is subject to change without

Seite 114 - Using Site Manager

Configuring GRE, NAT, RIPSO, and BFE ServicesA-10308625-14.20 Rev 00Parameter: Mapping Timeout (secs)Path: Configuration Manager > Protocols > I

Seite 115

Site Manager Parameters308625-14.20 Rev 00A-11 NAT Interface ParametersThe NAT Interface List window allows access to NAT interface parameters. If you

Seite 116

Configuring GRE, NAT, RIPSO, and BFE ServicesA-12308625-14.20 Rev 00NAT Static Translation ParametersThe NAT Static Translation List window allows acc

Seite 117 - Logging NAT Messages

Site Manager Parameters308625-14.20 Rev 00A-13 Parameter: EnablePath: Configuration Manager > Protocols > IP > NAT > Static MappingDefault

Seite 118

Configuring GRE, NAT, RIPSO, and BFE ServicesA-14308625-14.20 Rev 00Parameter: Source DomainPath: Configuration Manager > Protocols > IP > NA

Seite 119

Site Manager Parameters308625-14.20 Rev 00A-15 Parameter: Destination DomainPath: Configuration Manager > Protocols > IP > NAT > Static Ma

Seite 120

Configuring GRE, NAT, RIPSO, and BFE ServicesA-16308625-14.20 Rev 00Adding Static Translation ParametersTo add static translations, whether bidirectio

Seite 121

Site Manager Parameters308625-14.20 Rev 00A-17 Depending on the type of configuration you want, go to the appropriate section:Adding NAT Bidirectional

Seite 122 - Customizing a NAT Interface

Configuring GRE, NAT, RIPSO, and BFE ServicesA-18308625-14.20 Rev 00Parameter: Source DomainPath: Configuration Manager > Protocols > IP > NA

Seite 123

Site Manager Parameters308625-14.20 Rev 00A-19 Parameter: Destination DomainPath: Configuration Manager > Protocols > IP > NAT > Static Ma

Seite 124

308625-14.20 Rev 001-1 Chapter 1Configuring GRE TunnelsThis chapter provides information about Generic Routing Encapsulation (GRE) tunnels and instruc

Seite 125

Configuring GRE, NAT, RIPSO, and BFE ServicesA-20308625-14.20 Rev 00Adding NAT SDPT ParametersTo configure NAT static destination port translation (SD

Seite 126

Site Manager Parameters308625-14.20 Rev 00A-21 Parameter: Private PortPath: Configuration Manager > Protocols > IP > NAT > Static Mapping

Seite 127

Configuring GRE, NAT, RIPSO, and BFE ServicesA-22308625-14.20 Rev 00Adding NAT Unidirectional ParametersTo configure static, unidirectional NAT, set t

Seite 128

Site Manager Parameters308625-14.20 Rev 00A-23 Parameter: Static NexthopPath: Configuration Manager > Protocols > IP > NAT > Static Mappin

Seite 129

Configuring GRE, NAT, RIPSO, and BFE ServicesA-24308625-14.20 Rev 00NAT Dynamic Mapping ParametersTo access the NAT dynamic mapping configuration wind

Seite 130

Site Manager Parameters308625-14.20 Rev 00A-25 NAT Source Address Filter ParametersThe following parameters are accessible from the NAT Source Address

Seite 131 - The results of the

Configuring GRE, NAT, RIPSO, and BFE ServicesA-26308625-14.20 Rev 00Parameter: Translation Pool SelectorPath: Configuration Manager > Protocols >

Seite 132 - in-domain-name

Site Manager Parameters308625-14.20 Rev 00A-27 Parameter: Static NexthopPath: Configuration Manager > Protocols > IP > NAT > Dynamic Mappi

Seite 133 - DNS proxy

Configuring GRE, NAT, RIPSO, and BFE ServicesA-28308625-14.20 Rev 00Adding Source Address Filter ParametersThe following parameters are accessible whe

Seite 134

Site Manager Parameters308625-14.20 Rev 00A-29 Parameter: Domain NamePath: Configuration Manager > Protocols > IP > NAT > Dynamic Mapping

Seite 135

Configuring GRE, NAT, RIPSO, and BFE Services1-2308625-14.20 Rev 00GRE Concepts and TerminologyGeneric Routing Encapsulation (GRE) is a protocol that

Seite 136

Configuring GRE, NAT, RIPSO, and BFE ServicesA-30308625-14.20 Rev 00Parameter: Nto1 AddressPath: Configuration Manager > Protocols > IP > NAT

Seite 137

Site Manager Parameters308625-14.20 Rev 00A-31 NAT Translation Pool ParametersThe following parameters are accessible from the NAT Translation Pool Li

Seite 138

Configuring GRE, NAT, RIPSO, and BFE ServicesA-32308625-14.20 Rev 00Adding NAT Translation Pool ParametersThe following parameters are accessible when

Seite 139

Site Manager Parameters308625-14.20 Rev 00A-33 Parameter: Prefix LengthPath: Configuration Manager > Protocols > IP > NAT > Dynamic Mappin

Seite 140

Configuring GRE, NAT, RIPSO, and BFE ServicesA-34308625-14.20 Rev 00RIPSO ParametersThe IP Interface List window (Figure A-3) allows access to paramet

Seite 141

Site Manager Parameters308625-14.20 Rev 00A-35 Parameter: Enable SecurityPath: Configuration Manager > Protocols > IP > InterfacesDefault: En

Seite 142

Configuring GRE, NAT, RIPSO, and BFE ServicesA-36308625-14.20 Rev 00Parameter: Require Out SecurityPath: Configuration Manager > Protocols > IP

Seite 143

Site Manager Parameters308625-14.20 Rev 00A-37 Parameter: Minimum LevelPath: Configuration Manager > Protocols > IP > InterfacesDefault: Uncl

Seite 144

Configuring GRE, NAT, RIPSO, and BFE ServicesA-38308625-14.20 Rev 00Parameter: Must Out AuthorityPath: Configuration Manager > Protocols > IP &g

Seite 145 - Site Manager 2-102

Site Manager Parameters308625-14.20 Rev 00A-39 Parameter: Must In AuthorityPath: Configuration Manager > Protocols > IP > InterfacesDefault:

Seite 146

Configuring GRE Tunnels308625-14.20 Rev 001-3 How GRE Tunneling WorksA simple point-to-point GRE tunnel terminates at router interfaces at each end of

Seite 147

Configuring GRE, NAT, RIPSO, and BFE ServicesA-40308625-14.20 Rev 00Parameter: Implicit LabelPath: Configuration Manager > Protocols > IP > I

Seite 148

Site Manager Parameters308625-14.20 Rev 00A-41 Parameter: Implicit LevelPath: Configuration Manager > Protocols > IP > InterfacesDefault: Unc

Seite 149

Configuring GRE, NAT, RIPSO, and BFE ServicesA-42308625-14.20 Rev 00Parameter: Default AuthorityPath: Configuration Manager > Protocols > IP >

Seite 150

Site Manager Parameters308625-14.20 Rev 00A-43 Parameter: Error LabelPath: Configuration Manager > Protocols > IP > InterfacesDefault: Enable

Seite 152

308625-14.20 Rev 00B-1 Appendix BSample Bidirectional NAT ConfigurationPROBLEM: Hosts in two domains at your site need to share information, yet you n

Seite 153

Configuring GRE, NAT, RIPSO, and BFE ServicesB-2308625-14.20 Rev 00The configuration tasks are similar when configuring static bidirectional NAT, exce

Seite 154 - Adding a Translation Pool

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-3 The address translation at the NAT router occurs with the assistance of BayRS DNS proxy o

Seite 155

Configuring GRE, NAT, RIPSO, and BFE ServicesB-4308625-14.20 Rev 001. Configure a DNS server with a public address on the same network as the router t

Seite 156

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-5 Configuring RIP2 on the router IP interface 25.2.2.2 for domain1:ip/25.2.2.2/255.0.0.0# r

Seite 157

Configuring GRE, NAT, RIPSO, and BFE Services1-4308625-14.20 Rev 00The GRE tunnel can use any IP interface configured on the router as a physical end

Seite 158

Configuring GRE, NAT, RIPSO, and BFE ServicesB-6308625-14.20 Rev 00fwd-port 53fwd-server1-address 99.9.9.9fwd-server2-address 0.0.0.0fwd-server3-addre

Seite 159 - Deleting a Translation Pool

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-7 To view the status of the NAT interfaces on the router, enter the show nat interfaces com

Seite 160

Configuring GRE, NAT, RIPSO, and BFE ServicesB-8308625-14.20 Rev 00To check the addresses in a source address filter and to see whether a source addre

Seite 161

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-9 8.Configure DNS client on each device in the domains that will initiate IP traffic whose

Seite 162

Configuring GRE, NAT, RIPSO, and BFE ServicesB-10308625-14.20 Rev 00Checking Address TranslationsAfter you configure your router for bidirectional NAT

Seite 163 - Chapter 3

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-11 show nat domains (BCC)The command show nat domains displays address translations for the

Seite 164

Configuring GRE, NAT, RIPSO, and BFE ServicesB-12308625-14.20 Rev 00• The fourth translation is for host B (4.1.1.1) in the inbound domain (domain2.ne

Seite 165 - Security Label Format

Sample Bidirectional NAT Configuration308625-14.20 Rev 00B-13 • The output columns IP Protocol (UDP, TCP, or none are possible values), Original Port,

Seite 166 - Inbound IP Datagrams

Configuring GRE, NAT, RIPSO, and BFE ServicesB-14308625-14.20 Rev 00The output columns Original Port and Translated Port display port number informati

Seite 167 - Unlabeled IP Datagrams

308625-14.20 Rev 00Index-1Aaccept policies, configuring for GRE tunnels, 1-7, 1-8acronyms, xviiaddress translation precedence (NAT), 2-35aging (NAT),

Seite 168 - Enabling and Disabling RIPSO

Configuring GRE Tunnels308625-14.20 Rev 001-5 Figure 1-2. GRE Tunnel Encapsulating the IP ProtocolGRE Packet HeadersThe previous example followed the

Seite 169

Index-2308625-14.20 Rev 00delete command (BCC)GREremote tunnel end point, 1-26tunnel, 1-27tunnel protocol, 1-24NATfrom a router interface, 2-79source

Seite 170

308625-14.20 Rev 00Index-3EECMP support limitation for NAT, 2-33Enable parameterGREremote tunnel end point, 1-26, A-5tunnel, 1-22, A-4NATglobal, 2-66,

Seite 171

Index-4308625-14.20 Rev 00LL1 Default Metric parameter (OSI), 1-15L1 Designated Router Priority parameter (OSI), 1-15L2 Default Metric parameter (OSI)

Seite 172

308625-14.20 Rev 00Index-5NAT (continued)dynamic translations (continued)reenabling a source address filter, 2-103reenabling a translation pool, 2-109

Seite 173

Index-6308625-14.20 Rev 00NAT (continued)translation pool (continued)disabling, 2-109enabling, 2-109more than one in a domain, 2-11pairing with source

Seite 174

308625-14.20 Rev 00Index-7publicationshard copy, xixrelated, xviiiRRedirect Enable/Disable parameter (OSI), 1-15reenablingGREremote tunnel end point,

Seite 175

Index-8308625-14.20 Rev 00security classification (RIPSO), 3-4security labels (RIPSO)format, 3-3specifying inbound datagram types that require, 3-9spe

Seite 176 - Outbound Datagrams

308625-14.20 Rev 00Index-9timeout (NAT)aging, enabling/disabling, 2-71value, configuring for dynamic translations, 2-72timeout command (BCC), 2-71time

Seite 178 - RIPSO Example

Configuring GRE, NAT, RIPSO, and BFE Services1-6308625-14.20 Rev 00Figure 1-3. GRE Packet HeadersThe outermost (delivery) header is an IP header with

Seite 179 - Figure 3-2. RIPSO Example

Configuring GRE Tunnels308625-14.20 Rev 001-7 Requirements for GRE Tunnels Encapsulating IP ProtocolBefore configuring a tunnel encapsulating IP, you

Seite 180

Configuring GRE, NAT, RIPSO, and BFE Services1-8308625-14.20 Rev 00The disadvantage of using an announce policy is that it prevents the advertisement

Seite 181 - Chapter 4

Configuring GRE Tunnels308625-14.20 Rev 001-9 Number of Tunnels Configurable per RouterThe number of GRE tunnels you can configure on a router varies,

Seite 182

308625-14.20 Rev 00iiiNortel Networks NA Inc. Software License AgreementNOTICE: Please carefully read this license agreement before copying or using t

Seite 183

Configuring GRE, NAT, RIPSO, and BFE Services1-10308625-14.20 Rev 00Creating a GRE TunnelTo create a tunnel:1. Configure the local tunnel end point.2.

Seite 184 - BFE Addressing

Configuring GRE Tunnels308625-14.20 Rev 001-11 name is a unique name for this tunnel.address is a valid IP address of a local router interface express

Seite 185 - Configuring BFE Support

Configuring GRE, NAT, RIPSO, and BFE Services1-12308625-14.20 Rev 00Adding a Protocol to the Local Tunnel End PointThe Nortel Networks implementation

Seite 186

Configuring GRE Tunnels308625-14.20 Rev 001-13 Adding an IPX Protocol InterfaceTo add an IPX protocol interface to the local tunnel end point, navigat

Seite 187

Configuring GRE, NAT, RIPSO, and BFE Services1-14308625-14.20 Rev 00Adding an OSI Protocol InterfaceTo add the OSI protocol to the local tunnel end po

Seite 188

Configuring GRE Tunnels308625-14.20 Rev 001-15 6. Set the following parameters (required if OSI has not been configured previously on any other router

Seite 189

Configuring GRE, NAT, RIPSO, and BFE Services1-16308625-14.20 Rev 00Configuring the Remote Tunnel End PointA remote tunnel end point can be any IP int

Seite 190

Configuring GRE Tunnels308625-14.20 Rev 001-17 Using the BCCTo configure a remote tunnel end point using the BCC, complete the following steps.Step 1.

Seite 191 - Site Manager Parameters

Configuring GRE, NAT, RIPSO, and BFE Services1-18308625-14.20 Rev 00Configuring a Remote Logical IP InterfaceTo configure a remote logical IP interfac

Seite 192 - GRE Parameters

Configuring GRE Tunnels308625-14.20 Rev 001-19 Using Site ManagerConfiguring a Remote End Point for IP or IPXTo configure a remote tunnel end point fo

Seite 193

iv308625-14.20 Rev 00for the security of its own data and information and for maintaining adequate procedures apart from the Software to reconstruct

Seite 194 - Remote Connection Parameters

Configuring GRE, NAT, RIPSO, and BFE Services1-20308625-14.20 Rev 00Configuring a Remote End Point for OSITo configure a remote tunnel end point for t

Seite 195

Configuring GRE Tunnels308625-14.20 Rev 001-21 Customizing a GRE TunnelYou can customize a configured GRE tunnel, as described in the following sectio

Seite 196

Configuring GRE, NAT, RIPSO, and BFE Services1-22308625-14.20 Rev 00Using Site ManagerTo disable or reenable a GRE tunnel, complete the following task

Seite 197 - NAT Parameters

Configuring GRE Tunnels308625-14.20 Rev 001-23 For example, the following command disables the IP protocol interface 9.9.9.1/255.255.255.0:ip/9.9.9.1/

Seite 198 - Caution:

Configuring GRE, NAT, RIPSO, and BFE Services1-24308625-14.20 Rev 00Deleting a Protocol from a GRE TunnelUse the BCC or Site Manager to delete a proto

Seite 199

Configuring GRE Tunnels308625-14.20 Rev 001-25 Disabling and Reenabling a Remote Tunnel End PointWhen you configure a remote tunnel end point, it is e

Seite 200

Configuring GRE, NAT, RIPSO, and BFE Services1-26308625-14.20 Rev 00Using Site ManagerTo disable or reenable a remote tunnel end point, complete the f

Seite 201 - NAT Interface Parameters

Configuring GRE Tunnels308625-14.20 Rev 001-27 Using Site ManagerTo delete a remote tunnel end point, complete the following tasks:Deleting a GRE Tunn

Seite 202

Configuring GRE, NAT, RIPSO, and BFE Services1-28308625-14.20 Rev 00Using Site ManagerTo delete a GRE tunnel, complete the following tasks: Site Manag

Seite 203

308625-14.20 Rev 002-1Chapter 2Configuring Network Address TranslationThis chapter describes network address translation (NAT) and provides instructio

Seite 204

308625-14.20 Rev 00vContents PrefaceText Conventions ...

Seite 205

Configuring GRE, NAT, RIPSO, and BFE Services2-2308625-14.20 Rev 00NAT ConceptsNetwork Address Translation is a method by which IP addresses are mappe

Seite 206

Configuring Network Address Translation308625-14.20 Rev 002-3Unidirectional NATFor unidirectional NAT, the translation is done for addresses within th

Seite 207

Configuring GRE, NAT, RIPSO, and BFE Services2-4308625-14.20 Rev 00RequirementsIn addition to configuring NAT on the router, unidirectional NAT (inclu

Seite 208

Configuring Network Address Translation308625-14.20 Rev 002-5Representing Multiple Hosts with a Single Address: SDPT and N-to-1For TCP and UDP traffic

Seite 209

Configuring GRE, NAT, RIPSO, and BFE Services2-6308625-14.20 Rev 00The major difference between SDPT and N-to-1 translation is that N-to-1 applies onl

Seite 210 - Adding NAT SDPT Parameters

Configuring Network Address Translation308625-14.20 Rev 002-7Bidirectional (Multidomain) NATBidirectional multidomain NAT is a unique feature of BayRS

Seite 211

Configuring GRE, NAT, RIPSO, and BFE Services2-8308625-14.20 Rev 00• Install Domain Name System (DNS) server on a machine with a public interface to t

Seite 212

Configuring Network Address Translation308625-14.20 Rev 002-9The DNS proxy server accepts DNS name service requests from hosts on either side of the r

Seite 213

Configuring GRE, NAT, RIPSO, and BFE Services2-10308625-14.20 Rev 00Translation ModesYou can configure your router so that network address translation

Seite 214

Configuring Network Address Translation308625-14.20 Rev 002-11Dynamic Translation ModeNAT dynamic translation mode allows you to configure a temporary

Seite 215

vi308625-14.20 Rev 00Using the BCC ...1-17Step 1

Seite 216

Configuring GRE, NAT, RIPSO, and BFE Services2-12308625-14.20 Rev 00Comparing unidirectional and bidirectional dynamic NAT You can configure unidirect

Seite 217

Configuring Network Address Translation308625-14.20 Rev 002-13For instructions on how to configure mapping aging, see:• “Enabling and Disabling the Dy

Seite 218

Configuring GRE, NAT, RIPSO, and BFE Services2-14308625-14.20 Rev 00Unidirectional NATYou can configure the following types of unidirectional NAT: sta

Seite 219

Configuring Network Address Translation308625-14.20 Rev 002-15Dynamic Unidirectional Address TranslationNAT routers translate host addresses from insi

Seite 220

Configuring GRE, NAT, RIPSO, and BFE Services2-16308625-14.20 Rev 00Figure 2-2. Network Address Translation ExampleBostonAtlantaNew YorkSanta ClaraLon

Seite 221

Configuring Network Address Translation308625-14.20 Rev 002-17When the router’s NAT interface receives a packet, the NAT router extracts the source ad

Seite 222

Configuring GRE, NAT, RIPSO, and BFE Services2-18308625-14.20 Rev 00In Figure 2-4, the NAT router dynamically translates the source address, 10.0.0.15

Seite 223

Configuring Network Address Translation308625-14.20 Rev 002-19In Figure 2-5, the NAT router then replaces the private source address (10.0.0.15) with

Seite 224 - RIPSO Parameters

Configuring GRE, NAT, RIPSO, and BFE Services2-20308625-14.20 Rev 00The destination host uses the incoming packet’s source address to create a destina

Seite 225

Configuring Network Address Translation308625-14.20 Rev 002-21Figure 2-6. Sample Configuration for NAT SDPTThe HTTP server actually has a local IP add

Seite 226

308625-14.20 Rev 00viiStatic Destination and Port Translation (SDPT) ...2-20Network Address Port Translat

Seite 227

Configuring GRE, NAT, RIPSO, and BFE Services2-22308625-14.20 Rev 00It might seem as if this HTTP server has two identities: The server has its actual

Seite 228

Configuring Network Address Translation308625-14.20 Rev 002-23When TCP packets with a destination address of 192.32.29.17 arrive in the NAT-configured

Seite 229

Configuring GRE, NAT, RIPSO, and BFE Services2-24308625-14.20 Rev 00Figure 2-7. N-to-1 Translation (Part 1)The following events occur:1. NAT receives

Seite 230

Configuring Network Address Translation308625-14.20 Rev 002-252. NAT uses the address and the port number to identify the destination host.3. NAT repl

Seite 231

Configuring GRE, NAT, RIPSO, and BFE Services2-26308625-14.20 Rev 00Bidirectional NATYou can configure bidirectional NAT statically or dynamically, an

Seite 232

Configuring Network Address Translation308625-14.20 Rev 002-27When host A transmits packets to the NAT router, NAT replaces the source address in the

Seite 233

Configuring GRE, NAT, RIPSO, and BFE Services2-28308625-14.20 Rev 00Dynamic Bidirectional Address Translation with Two DomainsFigure 2-10 offers an ex

Seite 234

Configuring Network Address Translation308625-14.20 Rev 002-29A source address filter and translation pool are configured in each domain. Host A in do

Seite 235 - Appendix B

Configuring GRE, NAT, RIPSO, and BFE Services2-30308625-14.20 Rev 00Host A in domain 1 receives the DNS response message and saves the translation IP

Seite 236 - Sample Scenario

Configuring Network Address Translation308625-14.20 Rev 002-31Host B receives packets from and sends replies back to host A. The reply packets will ha

Seite 237

viii308625-14.20 Rev 00Customizing a NAT Interface ...2-74Addin

Seite 238

Configuring GRE, NAT, RIPSO, and BFE Services2-32308625-14.20 Rev 00NAT Implementation GuidelinesBefore you implement a NAT configuration, you should

Seite 239

Configuring Network Address Translation308625-14.20 Rev 002-33Protocol Requirements and CompatibilitiesConsider the following guidelines related to pr

Seite 240

Configuring GRE, NAT, RIPSO, and BFE Services2-34308625-14.20 Rev 00Compatibility of NAT and IPsec on a Router InterfaceYou can configure both unidire

Seite 241

Configuring Network Address Translation308625-14.20 Rev 002-35However, NAT SDPT support requires that you combine several translation types in your co

Seite 242

Configuring GRE, NAT, RIPSO, and BFE Services2-36308625-14.20 Rev 00When N-to-1 dynamic port translation is enabled, the source address (private inter

Seite 243

Configuring Network Address Translation308625-14.20 Rev 002-37Figure 2-14 illustrates a NAT configuration in which a dynamic address range encloses an

Seite 244 - Checking Address Translations

Configuring GRE, NAT, RIPSO, and BFE Services2-38308625-14.20 Rev 00Figure 2-15 illustrates configured NAT ranges that do not overlap. Packets with a

Seite 245 - <IP_address>

Configuring Network Address Translation308625-14.20 Rev 002-39Internet Control Message Protocol and Message HandlingNAT automatically allows Internet

Seite 246

Configuring GRE, NAT, RIPSO, and BFE Services2-40308625-14.20 Rev 00Starting NAT Services and Configuring TranslationsThis section provides instructio

Seite 247

Configuring Network Address Translation308625-14.20 Rev 002-41Step 1. Add NAT to a router interfaceTo configure NAT on a router interface, navigate to

Seite 248

308625-14.20 Rev 00ixSpecifying the Outbound Datagram Type Requiring Security Labels ...3-8Specifying the Inbound Datagram T

Seite 249

Configuring GRE, NAT, RIPSO, and BFE Services2-42308625-14.20 Rev 00prefix_length specifies the end of the IP address range available for translation.

Seite 250

Configuring Network Address Translation308625-14.20 Rev 002-43When configuring unidirectional NAT, you must use the special domain name “public” to id

Seite 251

Configuring GRE, NAT, RIPSO, and BFE Services2-44308625-14.20 Rev 00The info command lets you see the values configured so far for this source address

Seite 252

Configuring Network Address Translation308625-14.20 Rev 002-45Using Site ManagerBefore you can start NAT on the router, you must configure a circuit t

Seite 253

Configuring GRE, NAT, RIPSO, and BFE Services2-46308625-14.20 Rev 00Step 2. Configure the NAT public interfaceFor unidirectional NAT, the public inter

Seite 254

Configuring Network Address Translation308625-14.20 Rev 002-47Step 3. Configuring a source address filterFor unidirectional NAT, the source address fi

Seite 255

Configuring GRE, NAT, RIPSO, and BFE Services2-48308625-14.20 Rev 00Step 4. Configuring a translation poolThe translation pool specifies to the router

Seite 256

Configuring Network Address Translation308625-14.20 Rev 002-497. Set the following parameters:• IP Address• Prefix Length• Domain NameClick on Help or

Seite 257

Configuring GRE, NAT, RIPSO, and BFE Services2-50308625-14.20 Rev 00Configuring Bidirectional NAT (Dynamic)In the following bidirectional multidomain

Seite 258

Configuring Network Address Translation308625-14.20 Rev 002-51Step 1. Install DNS server on a device with a public interface to the NAT routerYou must

Kommentare zu diesen Handbüchern

Keine Kommentare