Ubiquiti EdgeRouter [29/57] Destination nat rules

Ubiquiti EdgeRouter [29/57] Destination nat rules
26
Chapter 5: Security TabEdgeOS
User Guide
Ubiquiti Networks, Inc.
Enable Logging Check this box to log instances when
the rule is matched.
Protocol Select one of the following:
- All protocols Match packets of all protocols.
- TCP Match TCP packets.
- UDP Match UDP packets.
- Both TCP and UDP Match TCP and UDP packets.
- Choose a protocol by name Select the protocol from
the drop-down list. Match packets of this protocol.
Match all protocols except for this Match packets
of all protocols except for the selected protocol.
- Enter a protocol number Enter the port number of
the protocol. Match packets of this protocol.
Match all protocols except for this Match packets
of all protocols except for the selected protocol.
Src Address Enter the IP address or network address of
the source. You can also enter a range of IP addresses;
one of them will be used.
Note: If you enter a network address, enter the IP
address and subnet mask using slash notation:
<network_IP_address>/<subnet_mask_number>
(example: 192.0.2.0/24).
Src Port Enter the port name or number of the source.
You can also enter a range of port numbers; one of them
will be used.
NAT groups are created on the Firewall/NAT Groups
tab; see “Firewall/NAT Groups” on page 28 for
more information. Select the appropriate group(s);
you can specify up to two groups maximum in these
combinations:
• An address group and port group
• A network group and port group
The packets must match both groups to apply the rule.
Src Address Group or Interface Addr. Select the
appropriate address group or interface address. If you
select Other as the interface address, then enter the
interface name in the field provided. The NAT rule will
match the IP address of the selected interface.
Src Network Group Select the appropriate network
group.
Src Port Group Select the appropriate port group.
Dest. Address Enter the IP address or network address
of the destination. You can also enter a range of IP
addresses; one of them will be used.
Note: If you enter a network address, enter the IP
address and subnet mask using slash notation:
<network_IP_address>/<subnet_mask_number>
(example: 192.0.2.0/24).
Dest. Port Enter the port name or number of the
destination. You can also enter a range of port numbers;
one of them will be used.
Dest Address Group or Interface Addr. Select the
appropriate address group or interface address. If you
select Other as the interface address, then enter the
interface name in the field provided. The NAT rule will
match the IP address of the selected interface.
Dest Network Group Select the appropriate network
group.
Dest Port Group Select the appropriate port group.
Click Save to apply your changes, or click Cancel.
Destination NAT Rules
Destination NAT Rules change the destination address of
packets; a typical scenario is that a public source needs
to communicate with a private destination. A Destination
NAT Rule goes from the public network to the private
network and is applied before routing.
Add Destination NAT Rule To create a new rule, click
Add Destination NAT Rule. Go to the Add or Configure a
Destination NAT Rule section.
Save Rule Order To change the rule order, click and drag
a rule up or down the sequence, and then release the rule.
When you are finished, click Save Rule Order.
Search Allows you to search for specific text. Begin
typing; there is no need to press enter. The results are
filtered in real time as soon as you type two or more
characters.

Содержание

Похожие устройства

Скачать