About NAT address mapping

Prev Next

To implement NAT deployment in a Central Management System network, a network administrator needs to map source-to-destination IP address and port pairs so a connection to the managed Malware Analysis appliance behind the NAT gateway can be established. Managed appliances can use either one or two ports for the connection and for the management and DTI network traffic. By default, one port is used. The steps for switching between single-port and dual-port communication in a NAT deployment are described in Restoring single-port communication using the CLI .

Port accessibility for single-port communication

For a single-port configuration, the remote management (SSH) port needs to be accessible. This port is used to initiate the connection, to configure and monitor the appliance, and to request software updates (such as security content, guest images, and system images) from the DTI source server. Port 22 is the default.

Port accessibility for dual-port communication

For a dual-port configuration, the following ports need to be accessible:

  • Remote management (SSH) port—The management port used to initiate the connection, and for the Central Management System appliance to use to configure and monitor the appliance. Port 22 is the default.

  • DTI network service (HTTPS) port—The port used to request software updates (such as security content, guest images, and system images) from the DTI source server. Port 443 is the default.

  • DTI address for the Central Management System platform—If the Central Management System appliance is behind a NAT gateway, the network administrator must map an accessible DTI server IP address and HTTPS port. For details, see Configuring and activating an accessible DTI server address .