Page 126 / 228 Scroll up to view Page 121 - 125
Chapter 9 Network Address Translation (NAT)
ericom D1000 modem User’s Guide
126
Port Forwarding
A port forwarding set is a list of inside (behind NAT on the LAN) servers, for example, web or FTP,
that you can make visible to the outside world even though NAT makes your whole inside network
appear as a single computer to the outside world.
Finding Out More
See
Section 9.6 on page 130
for advanced technical information on NAT.
9.2
The NAT General Screen
Use this screen to activate NAT for the default WAN connection (PVC0). Click
Network Setting >
NAT
to open the following screen.
Note: You must create an IP filter rule in addition to setting up NAT, to allow traffic from
the WAN to be forwarded through the Device.
Figure 85
Network Setting > NAT > General
The following table describes the labels in this screen.
Table 42
Network Setting > NAT > General
LABEL
DESCRIPTION
Active
Select this check box to enable NAT.
Max NAT/Firewall
Session Per User
When computers use peer to peer applications, such as file sharing applications, they
need to establish NAT sessions. If you do not limit the number of NAT sessions a single
client can establish, this can result in all of the available NAT sessions being used. In
this case, no additional NAT sessions can be established, and users may not be able to
access the Internet.
Each NAT session establishes a corresponding firewall session. Use this field to limit the
number of NAT/Firewall sessions client computers can establish through the Device.
If your network has a small number of clients using peer to peer applications, you can
raise this number to ensure that their performance is not degraded by the number of
NAT sessions they can establish. If your network has a large number of users using peer
to peer applications, you can lower this number to ensure no single client is exhausting
all of the available NAT sessions.
Apply
Click this to save your changes.
Cancel
Click this to restore your previously saved settings.
Page 127 / 228
Chapter 9 Network Address Translation (NAT)
ericom D1000 modem User’s Guide
127
9.3
The Port Forwarding Screen
Use this screen to forward incoming service requests to the server(s) on your local network.
You may enter a single port number or a range of port numbers to be forwarded, and the local IP
address of the desired server. The port number identifies a service; for example, web service is on
port 80 and FTP on port 21. In some cases, such as for unknown services or where one server can
support more than one service (for example both FTP and web service), it might be better to
specify a range of port numbers. You can allocate a server IP address that corresponds to a port or
a range of ports.
Please refer to RFC 1700 for further information about port numbers.
Note: Many residential broadband ISP accounts do not allow you to run any server
processes (such as a Web or FTP server) from your location. Your ISP may
periodically check for servers and may suspend your account if it discovers any
active services at your location. If you are unsure, refer to your ISP.
Default Server IP Address
In addition to the servers for specified services, NAT supports a default server IP address. A default
server receives packets from ports that are not specified in this screen.
Note: If you do not assign a
Default Server
IP address, the Device discards all packets
received for ports that are not specified here or in the remote management setup.
9.3.1
Configuring the Port Forwarding Screen
Click
Network Setting > NAT > Port Forwarding
to open the following screen.
Note: Make sure NAT is activated on the WAN connection before you configure a port
forwarding rule for it. For the default WAN connection (PVC0), activate NAT in the
Network Setting > NAT > General
screen. For other WAN connections
(PVC1~PVC7), activate NAT for an individual WAN connection in the
Broadband
>
More Connections
>
Edit
screen.
Figure 86
Network Setting > NAT > Port Forwarding
Page 128 / 228
Chapter 9 Network Address Translation (NAT)
ericom D1000 modem User’s Guide
128
The following table describes the fields in this screen.
9.3.2
Port Forwarding Rule Add/Edit
Use this screen to add or edit a port forwarding rule. Click the
Add new rule
button or a rule’s edit
icon in the
Port Forwarding
screen to display the screen as shown next.
Figure 87
Network Setting > NAT > Port Forwarding: Add/Edit
The following table describes the fields in this screen.
Table 43
Network Setting > NAT > Port Forwarding
LABEL
DESCRIPTION
WAN Interface
Select a WAN connection for which you want to configure a port forwarding rule.
Add new rule
Click this button to add a rule to the table below.
#
This is the rule index number (read-only).
Active
This field indicates whether the rule is active or not.
Clear the check box to disable the rule. Select the check box to enable it.
Service Name
This is a service’s name.
External Start Port
This is the first port number of a port range that incoming service requests may use to
access the service in your local network.
External End Port
This is the last port number of a port range that incoming service requests may use to
access the service in your local network.
Internal Start Port
This is the starting port number that the device translates for the service in your local
network.
Internal End Port
This is the ending port number that the device translates for the service in your local
network.
Server IP Address
This is the server’s IP address in your local network.
Modify
Click the edit icon to go to the screen where you can edit the port forwarding rule.
Click the delete icon to delete an existing port forwarding rule. Note that subsequent
address mapping rules move up by one when you take this action.
Table 44
Network Setting > NAT > Port Forwarding: Edit
LABEL
DESCRIPTION
Active
Click this check box to enable the rule.
Service Name
Select the name of this port-forwarding rule.
Page 129 / 228
Chapter 9 Network Address Translation (NAT)
ericom D1000 modem User’s Guide
129
9.4
The DMZ Screen
If you need to allow packets from a specific WAN connection to your local network, NAT supports a
default server IP address. A default server receives packets from the specified WAN connection and
the ports that are not specified in the
NAT Port Forwarding Setup
screen.
Figure 88
Network Setting > NAT > DMZ
External Start
Port
Enter a port number in this field.
To forward only one port, enter the port number again in the
End Port
field.
To forward a series of ports, enter the start port number here and the end port number in
the
End Port
field.
External End Port
Enter a port number in this field.
To forward only one port, enter the port number in the
Start
Port
field above and then
enter it again in this field.
To forward a series of ports, enter the last port number in a series that begins with the
port number in the
Start Port
field above.
Server IP
Address
Enter the IP address of the server in your local network.
Protocol
Select the protocol of the service,
TCP
,
UDP
or
ALL
(TCP+UDP).
Open Start Port
Enter the first port number here to which you want the device to translate the incoming
port. For a range of ports, you only need to enter the first number of the range to which
you want the incoming ports translated, the device automatically calculates the last port of
the translated port range.
Open End Port
Enter the last port number here to which you want the device to translate the incoming
port. For a range of ports, you only need to enter the first number of the range to which
you want the incoming ports translated, the device automatically calculates the last port of
the translated port range.
Apply
Click this to save your changes.
Cancel
Click this to restore your previously saved settings.
Table 44
Network Setting > NAT > Port Forwarding: Edit
(continued)
LABEL
DESCRIPTION
Page 130 / 228
Chapter 9 Network Address Translation (NAT)
ericom D1000 modem User’s Guide
130
The following table describes the fields in this screen.
9.5
The ALG Screen
Some NAT routers may include a SIP Application Layer Gateway (ALG). A SIP ALG allows SIP calls
to pass through NAT by examining and translating IP addresses embedded in the data stream.
When the Device registers with the SIP register server, the SIP ALG translates the Device’s private
IP address inside the SIP data stream to a public IP address. You do not need to use STUN or an
outbound proxy if you enable this Device’s SIP ALG.
Use the
ALG
screen to enable and disable the SIP (VoIP) ALG in the Device. To access this screen,
click
Network Setting
>
NAT
>
ALG
.
Figure 89
Network Setting > NAT > ALG
The following table describes the fields in this screen.
9.6
NAT Technical Reference
This chapter contains more information regarding NAT.
Table 45
Network Setting > NAT > DMZ
LABEL
DESCRIPTION
WAN Interface
Select a WAN PVC connection (
PVC0
~
PVC7
) from which you want to forward the traffic
to the specified default server.
Default Server
Address
Enter the IP address of the default server which receives packets from ports that are not
specified in the
NAT > Port Forwarding
screen.
Note: If you do not assign a
Default Server Address
, the Device discards all packets
received for ports that are not specified in the
NAT Port Forwarding
screen.
Apply
Click
Apply
to save your changes.
Cancel
Click
Cancel
to restore your previously saved settings.
Table 46
Network Setting > NAT > ALG
LABEL
DESCRIPTION
ALG
Select
Enable
to make sure SIP (VoIP) works correctly with NAT.
Apply
Click
Apply
to save your changes.
Cancel
Click
Cancel
to restore your previously saved settings.

Rate

5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top