Ubiquiti EdgeRouter [30/57] Add or configure a destination nat rule

Ubiquiti EdgeRouter [30/57] Add or configure a destination nat rule
27
Chapter 5: Security TabEdgeOS
User Guide
Ubiquiti Networks, Inc.
A table displays the following information about each rule.
Click a column heading to sort by that heading.
Order The rules are applied in the order specified. The
number of the rule in this order is displayed.
Description The keywords you entered to describe this
rule are displayed.
Source Addr. The source IP address is displayed.
Source Port The source port number is displayed.
Dest. Addr. The destination IP address is displayed.
Dest. Port The destination port number is displayed.
Translation A description of the translation (such as to
<IP_address>) is displayed.
Count The number of translations is displayed.
Actions Click the Actions button to access the following
options:
Config To configure the rule, click Config. Go to the
Add or Configure a Destination NAT Rule section below.
Copy To create a duplicate, click Copy. The duplicate
rule appears at the bottom of the list.
Delete Remove the rule.
Add or Configure a Destination NAT Rule
After you click Config, the Destination NAT Rule
Configuration screen appears.
Description Enter keywords to describe this rule.
Enable Check the box to enable this rule.
Inbound Interface Select the interface through which
the incoming packets enter the EdgeRouter.
Translations Complete the following:
- Address Enter the IP address that will replace the
destination IP address of the incoming packet.
- Port Enter the port number that will replace the
destination port number of the incoming packet.
Exclude from NAT Check the box to exclude packets
that match this rule from NAT.
Enable Logging Check this box to log instances when
the rule is matched.
Protocol
- All protocols Match packets of all protocols.
- TCP Match TCP packets.
- UDP Match UDP packets.
- Both TCP and UDP Match TCP and UDP packets.
- Choose a protocol by name Select the protocol from
the drop-down list. Match packets of this protocol.
Match all protocols except for this Match packets
of all protocols except for the selected protocol.
- Enter a protocol number Enter the port number of
the protocol. Match packets of this protocol.
Match all protocols except for this Match packets
of all protocols except for the selected protocol.
Src Address Enter the IP address or network address of
the source. You can also enter a range of IP addresses;
one of them will be used.
Note: If you enter a network address, enter the IP
address and subnet mask using slash notation:
<network_IP_address>/<subnet_mask_number>
(example: 192.0.2.0/24).
Src Port Enter the port name or number of the source.
You can also enter a range of port numbers; one of them
will be used.
NAT groups are created on the Firewall/NAT Groups
tab; see “Firewall/NAT Groups” on page 28 for
more information. Select the appropriate group(s);
you can specify up to two groups maximum in these
combinations:
• An address group and port group
• A network group and port group
The packets must match both groups to apply the rule.

Содержание

Похожие устройства

Скачать