Action - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 5
Configuring Network Address Translation
Configuring Dynamic NAT and PAT as a Layer 3 and Layer 4
Policy-Map Action
OL-16202-01
Configure policy-map actions as required. For example, configure:
host1/C1(config-pmap-c)# loadbalance policy L7_POLICY
host1/C1(config-pmap-c)# loadbalance VIP inservice
For passive FTP, associate the FTP_NAT_CLASS class map (see the
a Class Map for Passive FTP
enter the following commands in policy map configuartion mode:
host1/C1(config)# policy-map multi-match NAT_POLICY
host1/C1(config-pmap)# class FTP_NAT_CLASS
Proceed with the following section and configure the nat dynamic command as a
policy action under the FTP class map if you are using passive FTP. Otherwise,
configure the nat dynamic command as a policy action under the NAT_CLASS
class map.
You can configure dynamic NAT and PAT (SNAT) as an action in a Layer 3 and
Layer 4 policy map by using the nat dynamic command in policy-map class
configuration mode. The ACE applies dynamic NAT from the interface to which
the traffic policy is attached (through the service-policy interface configuration
command) to the interface specified in the nat command. If you are operating in
one-arm mode, there is only one VLAN interface.
The syntax of this command is as follows:
nat dynamic pool_id vlan number
The keywords, arguments, and options are as follows:
dynamic pool_id—Refers to the identifier of a global pool of IP addresses
that was configured using the nat-pool command on the specified VLAN (see
the
"Creating a Global IP Address Pool for NAT"
translates a group of local source IP addresses to a pool of global IP addresses
that are routable on the destination network. All packets egressing the
interface attached to the traffic policy have their source address translated to
one of the available addresses in the global pool. Enter an integer from 1 to
2147483647.
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
Configuring Dynamic NAT and PAT
section) with the Layer 4 policy map. For example,
Configuring
section). Dynamic NAT
5-17

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents