
Step 1—Configuring Network Address Translation
Cisco 7100 Series VPN Configuration Guide
4-6
Figure 4-3 NAT Inside Source Translation
The following process describes inside source address translation, as shown in Figure 4-3:
1 The user at Host 10.1.1.1 opens a connection to Host B.
2 The firstpacket that the router receives from Host10.1.1.1 causes the router to check its
NAT table.
If a static translation entry was configured, the router goes to Step 3.
If no translation entry exists, the router determines that source address (SA) 10.1.1.1
mustbetranslateddynamically,selects a legal,global address from the dynamic address
pool, and creates a translation entry. This type of entry is called a simple entry.
3 The router replaces the inside local source address of Host 10.1.1.1 with the translation
entry’s global address, and forwards the packet.
4 Host B receives the packet and responds to Host 10.1.1.1 by using the inside global IP
destination address (DA) 10.2.2.2.
10.1.1.2
Host B
10.6.7.3
10.1.1.1
Internet
Inside
Inside
interface
Outside
interface
Outside
10.1.1.2
10.1.1.1
10.2.2.3
10.2.2.2
Inside local
IP address
NAT table
Inside global
IP address
1
3
SA
10.2.2.2
5
DA
10.1.1.1
SA
10.1.1.1
4
10.2.2.2
2
Comentarios a estos manuales