Mappings used when the File Protect appliance initiates the connection

Prev Next

This section shows the NAT address mapping required for each supported topology in which the File Protect appliance initiates the connection with the Central Management System appliance:

Some topologies use virtual IP addresses. These addresses are mapped on the NAT gateway to reach a Central Management System appliance or managed device that is in an internal network behind the gateway.

Note

Only those addresses that need mapping are shown. If no mapping is indicated, the default IP addresses and default ports (22, or 22 and 443) will be used.

Central Management System appliance is behind a NAT gateway

NAT address mappings are required for deployments in which the File Protect appliance initiates a connection to the Central Management System appliance behind a NAT gateway. The mapping details depend on whether the File Protect appliance is configured for single-port or dual-port communication.

Single-port Communication

If the File Protect appliance is configured for single-point communication and initiates a connection with the Central Management System appliance behind a NAT gateway, a virtual NAT IP address and port must be mapped to the internal Central Management System IP address and port 22.

The File Protect appliance uses the mapping to send a request to be added to the Central Management System appliance for management and also to request software updates.

CM_Int_EX_Initiates_sp_v2.jpg
Dual-port communication

If the File Protect appliance is configured for dual-port communication and initiates a connection with the Central Management System appliance behind a NAT gateway, a virtual NAT IP address and port must be mapped to the internal Central Management System IP address and port 22.

The File Protect appliance uses the mapping in order to send a request to be added to the Central Management System appliance for management and also to request software updates.

However, because the Central Management System appliance is in an internal network, the accessible DTI server IP address and HTTPS port must be mapped to the Central Management System internal IP address and port 443 so that the File Protect appliance can request software updates.

CM_IntNXInitiates_fig.jpg

File Protect appliance is behind a NAT gateway

No mapping is required because the Central Management System appliance is in an external network and the File Protect appliance can access it.

Central Management System and File Protect appliance are behind different NAT gateways

NAT address mappings are required for deployments in which the File Protect appliance initiates a connection to the Central Management System appliance and where the two devices are behind different NAT gateways. The mapping details depend on whether the File Protect appliance is configured for single-port or dual-port communication.

Single-port communication

If the File Protect appliance is configured for single-port communication and if the File Protect appliance and the Central Management System appliance are behind different NAT gateways, the virtual NAT gateway 1 IP address and port must be mapped to the Central Management System internal IP address and port 22.

The Central Management System appliance uses the mapping to configure and monitor the File Protect appliance. The File Protect appliance uses the mapping to send a request to be added to the Central Management System appliance for management and also to request software updates.

EX_Initiates_2NAT_sp_v2.jpg
Dual-port communication

If the File Protect appliance is configured for dual-port communication and if the File Protect appliance and the Central Management System appliance are behind different NAT gateways, the following NAT address mappings are required:

  • The virtual NAT gateway 1 IP address and port must be mapped to the Central Management System internal IP address and port 22. The mapping enables the File Protect appliance to send a request to be added to the Central Management System appliance for management and for the Central Management System appliance to configure and manage the appliance.

  • The File Protect appliance internal IP address and port 443 must be mapped to a virtual NAT gateway 2 IP address and port. The virtual NAT gateway 1 IP address and port must be mapped to the Central Management System internal IP address and port 443 for the File Protect appliance. The mappings enable the appliance to request software updates.

CM_NXInitiates2NAT_fig.jpg

Central Management System and File Protect appliance are in external networks

No NAT address mapping is required if the two devices are in external networks and the File Protect appliance initiates the connection.