C
h
a
p
t
e
r
8
NAT Configuration
Table of Contents
Overview
..........................................................................
83
Virtual Servers Setup
.........................................................
84
Port Triggering
..................................................................
87
DMZ Host
.........................................................................
89
Overview
Setting up the NAT
function
The 931WII is equipped with the
NAT
function. With address map-
ping, several users in the local network can access the Internet via
one or more public IP addresses. All the local IP addresses are as-
signed to the public IP address of the 931WII by default.
One of the characteristics of NAT is that data from the Internet is
not allowed into the local network unless it is explicitly requested
by one of the PCs in the network. Most Internet applications can
run behind the NAT firewall without any problems.
For example,
if you request Internet pages or send and receive e-mails, the
request for data from the Internet comes from a PC in the local
network, and so the 931WII allows the data to pass through. The
931WII opens one specific port for the application. A port in this
context is an internal PC address, via which the data is exchanged
between the Internet and a client on a PC in the local network.
Communicating via a port is subject to the rules of a particular
protocol (
TCP
or
UDP
).
If an external application tries to send a call to a PC in the local
network, the 931WII blocks it.
There is no open port via which
the data could enter the local network.
Some applications, such
as games on the Internet, require several links (that is.
several
ports), so that players can communicate with each other. In addi-
tion, these applications must also be permitted to send requests
from other users on the Internet to users in the local network.
These applications cannot be run if NAT is activated.
Using port forwarding (the forwarding of requests to particular
ports) the 931WII is forced to send requests from the Internet for
a certain service, for example, a game, to the appropriate port(s)
on the PC on which the game is running. Port triggering is a spe-
cial variant of port forwarding. Unlike port forwarding, the 931WII
forwards the data from the port block to the PC which has pre-
viously sent data to the Internet via a certain port (trigger port).
This means that approval for the data transfer is not tied to one
specific PC in the network, but rather to the port numbers of the
required Internet service.
Confidential and Proprietary Information of ZTE CORPORATION
83