<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 7102dl partial NAT in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/7102dl-partial-nat/m-p/4360829#M17485</link>
    <description>I think my original post didn't make clear that I know where the servers need to sit in terms of subnets (inside/outside), I just didn't know if enabling the firewall caused issues for normal routing (from the T1/frame relay interface) on the public interface.&lt;BR /&gt;&lt;BR /&gt;Let me confirm, for example:&lt;BR /&gt;&lt;BR /&gt;7102dl config (frame relay, but just showing the net interfaces):&lt;BR /&gt;eth 0/1: 192.168.0.1 (Private)&lt;BR /&gt;eth 0/2: xxx.xxx.xxx.1 (/27 Public IP Block)&lt;BR /&gt;secondary eth 0/2: xxx.xxx.xxx.2&lt;BR /&gt;&lt;BR /&gt;I know I can sit a server with ip 192.168.0.2 on the private network (gateway 192.168.0.1) and one-to-one NAT xxx.xxx.xxx.2 to 192.168.0.2. That shouldn't be a problem. &lt;BR /&gt;&lt;BR /&gt;The part I wasn't 100% sure on was, once the firewall is enabled, can I continue to have servers assigned with the remaining public IPs talking to eth 0/2?  I'm thinking this will work fine, since that interface is still visible, I just didn't know if I'd run into problems enabling the firewall to NAT a few of those public IP's.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 19 Feb 2009 12:50:44 GMT</pubDate>
    <dc:creator>Casey Morford</dc:creator>
    <dc:date>2009-02-19T12:50:44Z</dc:date>
    <item>
      <title>7102dl partial NAT</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/7102dl-partial-nat/m-p/4360827#M17483</link>
      <description>&lt;!--!*#--&gt;We have a 7102dl for routing our /27 block of IPs.&lt;BR /&gt;&lt;BR /&gt;Is is possible to NAT a few of the public IPs and just route the remaining IPs?  &lt;BR /&gt;&lt;BR /&gt;For example, a few of our servers have internal IP's only in the 10.0.0.0/8 subnet.  I'd like to do a one to one NAT from public to private IPs for those servers.  Some of our other servers are simply configured with the public IP.  &lt;BR /&gt;&lt;BR /&gt;By enabling the firewall, am I committed to NATing all of our public IPs, or, from what I've read in the forums, do I simply define the IPs I want NATed as secondary IPs on the public interface, and then the remaining public IPs will be routed as normal?</description>
      <pubDate>Tue, 17 Feb 2009 23:21:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/7102dl-partial-nat/m-p/4360827#M17483</guid>
      <dc:creator>Casey Morford</dc:creator>
      <dc:date>2009-02-17T23:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: 7102dl partial NAT</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/7102dl-partial-nat/m-p/4360828#M17484</link>
      <description>no,&lt;BR /&gt;all public adresses lay on the "outside" network.&lt;BR /&gt;&lt;BR /&gt;for incomming connections the firewall only listens to configured NAT adresses.&lt;BR /&gt;the other adresses are ignored by this firewall and can be used by another device on the outside network.&lt;BR /&gt;&lt;BR /&gt;for outgoing connections you may configure a NAT-pool, so multiple internal hosts can share public adresses.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;Pieter</description>
      <pubDate>Thu, 19 Feb 2009 09:52:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/7102dl-partial-nat/m-p/4360828#M17484</guid>
      <dc:creator>Pieter 't Hart</dc:creator>
      <dc:date>2009-02-19T09:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: 7102dl partial NAT</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/7102dl-partial-nat/m-p/4360829#M17485</link>
      <description>I think my original post didn't make clear that I know where the servers need to sit in terms of subnets (inside/outside), I just didn't know if enabling the firewall caused issues for normal routing (from the T1/frame relay interface) on the public interface.&lt;BR /&gt;&lt;BR /&gt;Let me confirm, for example:&lt;BR /&gt;&lt;BR /&gt;7102dl config (frame relay, but just showing the net interfaces):&lt;BR /&gt;eth 0/1: 192.168.0.1 (Private)&lt;BR /&gt;eth 0/2: xxx.xxx.xxx.1 (/27 Public IP Block)&lt;BR /&gt;secondary eth 0/2: xxx.xxx.xxx.2&lt;BR /&gt;&lt;BR /&gt;I know I can sit a server with ip 192.168.0.2 on the private network (gateway 192.168.0.1) and one-to-one NAT xxx.xxx.xxx.2 to 192.168.0.2. That shouldn't be a problem. &lt;BR /&gt;&lt;BR /&gt;The part I wasn't 100% sure on was, once the firewall is enabled, can I continue to have servers assigned with the remaining public IPs talking to eth 0/2?  I'm thinking this will work fine, since that interface is still visible, I just didn't know if I'd run into problems enabling the firewall to NAT a few of those public IP's.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 19 Feb 2009 12:50:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/7102dl-partial-nat/m-p/4360829#M17485</guid>
      <dc:creator>Casey Morford</dc:creator>
      <dc:date>2009-02-19T12:50:44Z</dc:date>
    </item>
  </channel>
</rss>

