This topic shows the NAT address mapping required for each supported topology in which the Central Management System appliance initiates the process of adding an appliance for management.
Some topologies use virtual IP addresses. These addresses are mapped on the NAT gateway to reach a Central Management System platform or managed device that is in an internal network behind the gateway.
Note
Only those addresses that need mapping are shown. If no mapping is indicated, the default IP addresses and default ports (22, or 22 and 443) will be used.
Central Management System appliance is behind a NAT gateway
This section describes the mappings required for deployments in which the Central Management System platform is behind the NAT gateway and initiates the connection to configure and manage the appliance.
Note
The following single-port diagrams use the Email Security — Server appliance as the managed appliance, and the dual-port diagrams use the Network Security appliance as the managed appliance. However, they are representative of other appliances as well.
Single-Port communication
No NAT address mapping is required if the Central Management System appliance initiates the connection and the Network Security appliance is in an external network and configured for single-port communication.
.jpg)
Dual-port communication
No NAT address mapping is required if the Central Management System appliance initiates the connection and the Network Security appliance is in an external network and configured for dual-port communication.
However, because the Central Management System platform is in an internal network, the accessible DTI server IP address and HTTPS port must be mapped to the Central Management System internal IP address and port 443 so that the Network Security appliance can request software updates.
.jpg)
Network Security appliance is behind a NAT gateway
NAT address mapping is required for deployments in which the Central Management System appliance initiates the connection to configure and manage the Network Security appliance that is behind a NAT gateway. The mapping details depend on whether the Network Security appliance is configured for single-port or dual-port communication.
Single-port communication
If the Central Management System appliance initiates the connection to the Network Security appliance that is behind a NAT gateway and configured for single-port communication, a virtual NAT IP address and port must be mapped to the Network Security appliance internal IP address and port 22.
The mapping enables the Central Management System appliance to initiate the connection and then configure and monitor the Network Security appliance. The Network Security appliance uses the mapping to request software updates.
.jpg)
Dual-port communication
If the Central Management System appliance initiates the connection to the Network Security appliance that is behind a NAT gateway and configured for dual-port communication, a virtual NAT IP address and port must be mapped to the Network Security appliance internal IP address and port 22.
The Central Management System appliance uses the mapping to initiate the connection and then configure and manage the Network Security appliance. Because the Central Management System appliance is in an external network, no mapping is required for the Network Security appliance to request software updates.
.jpg)
Central Management System and Network Security appliance are behind different NAT gateways
NAT address mappings are required for deployments in which the Central Management System appliance initiates the connection to the Network Security appliance and where the two devices are behind different NAT gateways. The mapping details depend on whether the Network Security appliance is configured for single-port or dual-port communication.
Single-port communication
If the Central Management System appliance initiates the connection, the Network Security appliance is configured for single-port communication, and the two devices are behind different NAT gateways, the virtual IP address and port of NAT gateway 2 must be mapped to the internal IP address and port 22 of the Network Security appliance.
The mapping enables the Central Management System appliance to initiate a connection and then configure and monitor the Network Security appliance, and for the Network Security appliance to request software updates.
.jpg)
Dual-port communication
If the Network Security appliance is configured for dual-port communication and if the Network Security appliance and the Central Management System appliance are behind different NAT gateways, the following NAT address mappings are required:
A virtual NAT gateway 2 IP address and port must be mapped to the Network Security appliance internal IP address and port 22. The mapping enables the Central Management System appliance to initiate the connection and then configure and monitor the Network Security appliance.
The accessible DTI server IP address and HTTPS port must be mapped to a virtual NAT gateway 1 IP address and port, and the virtual NAT gateway 1 IP address and port must be mapped to the Central Management System internal IP address and port 443. These mappings enable the Network Security appliance to request software updates.
.jpg)
Central Management System and Network Security appliance are in an external network
No NAT address mapping is required if the Central Management System appliance initiates the connection and the Network Security appliance is in an external network.