Ubiquiti EdgeRouter [28/57] Source nat rules

Ubiquiti EdgeRouter [28/57] Source nat rules
25
Chapter 5: Security TabEdgeOS
User Guide
Ubiquiti Networks, Inc.
Source NAT Rules
Source NAT Rules change the source address of packets;
a typical scenario is that a private source needs to
communicate with a public destination. A Source NAT
Rule goes from the private network to the public network
and is applied after routing, just before packets leave the
EdgeRouter.
Add Source NAT Rule To create a new rule, click Add
Source NAT Rule. Go to Add or Configure a Source NAT
Rule” on page 25.
Save Rule Order To change the rule order, click and drag
a rule up or down the sequence, and then release the rule.
When you are finished, click Save Rule Order.
Search Allows you to search for specific text. Begin
typing; there is no need to press enter. The results are
filtered in real time as soon as you type two or more
characters.
A table displays the following information about each rule.
Click a column heading to sort by that heading.
Order The rules are applied in the order specified. The
number of the rule in this order is displayed.
Description The keywords you entered to describe this
rule are displayed.
Source Addr. The source IP address is displayed.
Source Port The source port number is displayed.
Dest. Addr. The destination IP address is displayed.
Dest. Port The destination port number is displayed.
Translation A description of the translation (such as
masquerade to eth_) is displayed.
Count The number of translations is displayed.
Actions Click the Actions button to access the following
options:
Config To configure the rule, click Config. Go to the
Add or Configure a Source NAT Rule section below.
Copy To create a duplicate, click Copy. The duplicate
rule appears at the bottom of the list.
Delete Remove the rule.
Add or Configure a Source NAT Rule
After you click Config, the Source NAT Rule Configuration
screen appears.
Description Enter keywords to describe this rule.
Enable Check the box to enable this rule.
Outbound Interface Select the interface through
which the outgoing packets exit the EdgeRouter. This is
required only for Source NAT Rules that use Masquerade.
Translation Select one of the following:
- Use Masquerade Masquerade is a type of Source
NAT. If enabled, the source IP address of the packets
becomes the public IP address of the outbound
interface.
- Specify address and/or port If enabled, the source
IP address of the packets becomes the specified IP
address and port.
Address Enter the IP address that will replace the
source IP address of the outgoing packet. You can
also enter a range of IP addresses; one of them will
be used.
Port Enter the port number that will replace the
source port number of the outgoing packet. You
can also enter a range of port numbers; one of them
will be used.
Exclude from NAT Check the box to exclude packets
that match this rule from NAT.

Содержание

Похожие устройства

Скачать