Mappings used when the Central Management System appliance initiates the connection

Prev Next

This topic shows the NAT address mapping required for each supported topology in which the Central Management System appliance initiates the process of adding an appliance for management.

Some topologies use virtual IP addresses. These addresses are mapped on the NAT gateway to reach a Central Management System platform or managed device that is in an internal network behind the gateway.

Note

Only those addresses that need mapping are shown. If no mapping is indicated, the default IP addresses and default ports (22, or 22 and 443) will be used.

Central Management System appliance is behind a NAT gateway

This section describes the mappings required for deployments in which the Central Management System platform is behind the NAT gateway and initiates the connection to configure and manage the appliance.

Note

The following single-port diagrams use the Email Security — Server appliance as the managed appliance, and the dual-port diagrams use the Network Security appliance as the managed appliance. However, they are representative of other appliances as well.

Single-Port communication

No NAT address mapping is required if the Central Management System appliance initiates the connection and the File Protect appliance is in an external network and configured for single-port communication.

CM_Int_CM_Initiates_sp.jpg
Dual-port communication

No NAT address mapping is required if the Central Management System appliance initiates the connection and the File Protect appliance is in an external network and configured for dual-port communication.

However, because the Central Management System platform is in an internal network, the accessible DTI server IP address and HTTPS port must be mapped to the Central Management System internal IP address and port 443 so that the File Protect appliance can request software updates.

CM_IntCMInitiates_fig.jpg

File Protect appliance is behind a NAT gateway

NAT address mapping is required for deployments in which the Central Management System appliance initiates the connection to configure and manage the File Protect appliance that is behind a NAT gateway. The mapping details depend on whether the File Protect appliance is configured for single-port or dual-port communication.

Single-port communication

If the Central Management System appliance initiates the connection to the File Protect appliance that is behind a NAT gateway and configured for single-port communication, a virtual NAT IP address and port must be mapped to the File Protect appliance internal IP address and port 22.

The mapping enables the Central Management System appliance to initiate the connection and then configure and monitor the File Protect appliance. The File Protect appliance uses the mapping to request software updates.

EX_Int_CM_Initiates_sp_v2.jpg
Dual-port communication

If the Central Management System appliance initiates the connection to the File Protect appliance that is behind a NAT gateway and configured for dual-port communication, a virtual NAT IP address and port must be mapped to the File Protect appliance internal IP address and port 22.

The Central Management System appliance uses the mapping to initiate the connection and then configure and manage the File Protect appliance. Because the Central Management System appliance is in an external network, no mapping is required for the File Protect appliance to request software updates.

CM_NXIntCMInitiates_fig.jpg

Central Management System and File Protect appliance are behind different NAT gateways

NAT address mappings are required for deployments in which the Central Management System appliance initiates the connection to the File Protect appliance and where the two devices are behind different NAT gateways. The mapping details depend on whether the File Protect appliance is configured for single-port or dual-port communication.

Single-port communication

If the Central Management System appliance initiates the connection, the File Protect appliance is configured for single-port communication, and the two devices are behind different NAT gateways, the virtual IP address and port of NAT gateway 2 must be mapped to the internal IP address and port 22 of the File Protect appliance.

The mapping enables the Central Management System appliance to initiate a connection and then configure and monitor the File Protect appliance, and for the File Protect appliance to request software updates.

CM_Initiates_2NAT_sp_v2.jpg
Dual-port communication

If the File Protect appliance is configured for dual-port communication and if the File Protect appliance and the Central Management System appliance are behind different NAT gateways, the following NAT address mappings are required:

  • A virtual NAT gateway 2 IP address and port must be mapped to the File Protect appliance internal IP address and port 22. The mapping enables the Central Management System appliance to initiate the connection and then configure and monitor the File Protect appliance.

  • The accessible DTI server IP address and HTTPS port must be mapped to a virtual NAT gateway 1 IP address and port, and the virtual NAT gateway 1 IP address and port must be mapped to the Central Management System internal IP address and port 443. These mappings enable the File Protect appliance to request software updates.

CM_CMInitiates2NAT_fig.jpg

Central Management System and File Protect appliance are in an external network

No NAT address mapping is required if the Central Management System appliance initiates the connection and the File Protect appliance is in an external network.