This section shows the NAT address mapping required for each supported topology in which the Network Security appliance initiates the connection with the Central Management System appliance:
Some topologies use virtual IP addresses. These addresses are mapped on the NAT gateway to reach a Central Management System appliance or managed device that is in an internal network behind the gateway.
Note
Only those addresses that need mapping are shown. If no mapping is indicated, the default IP addresses and default ports (22, or 22 and 443) will be used.
Central Management System appliance is behind a NAT gateway
NAT address mappings are required for deployments in which the Network Security appliance initiates a connection to the Central Management System appliance behind a NAT gateway. The mapping details depend on whether the Network Security appliance is configured for single-port or dual-port communication.
Single-port Communication
If the Network Security appliance is configured for single-point communication and initiates a connection with the Central Management System appliance behind a NAT gateway, a virtual NAT IP address and port must be mapped to the internal Central Management System IP address and port 22.
The Network Security appliance uses the mapping to send a request to be added to the Central Management System appliance for management and also to request software updates.
.jpg)
Dual-port communication
If the Network Security appliance is configured for dual-port communication and initiates a connection with the Central Management System appliance behind a NAT gateway, a virtual NAT IP address and port must be mapped to the internal Central Management System IP address and port 22.
The Network Security appliance uses the mapping in order to send a request to be added to the Central Management System appliance for management and also to request software updates.
However, because the Central Management System appliance is in an internal network, the accessible DTI server IP address and HTTPS port must be mapped to the Central Management System internal IP address and port 443 so that the Network Security appliance can request software updates.
.jpg)
Network Security appliance is behind a NAT gateway
No mapping is required because the Central Management System appliance is in an external network and the Network Security appliance can access it.
Central Management System and Network Security appliance are behind different NAT gateways
NAT address mappings are required for deployments in which the Network Security appliance initiates a connection to the Central Management System appliance and where the two devices are behind different NAT gateways. The mapping details depend on whether the Network Security appliance is configured for single-port or dual-port communication.
Single-port communication
If the Network Security appliance is configured for single-port communication and if the Network Security appliance and the Central Management System appliance are behind different NAT gateways, the virtual NAT gateway 1 IP address and port must be mapped to the Central Management System internal IP address and port 22.
The Central Management System appliance uses the mapping to configure and monitor the Network Security appliance. The Network Security appliance uses the mapping to send a request to be added to the Central Management System appliance for management and also to request software updates.
.jpg)
Dual-port communication
If the Network Security appliance is configured for dual-port communication and if the Network Security appliance and the Central Management System appliance are behind different NAT gateways, the following NAT address mappings are required:
The virtual NAT gateway 1 IP address and port must be mapped to the Central Management System internal IP address and port 22. The mapping enables the Network Security appliance to send a request to be added to the Central Management System appliance for management and for the Central Management System appliance to configure and manage the appliance.
The Network Security appliance internal IP address and port 443 must be mapped to a virtual NAT gateway 2 IP address and port. The virtual NAT gateway 1 IP address and port must be mapped to the Central Management System internal IP address and port 443 for the Network Security appliance. The mappings enable the appliance to request software updates.
.jpg)
Central Management System and Network Security appliance are in external networks
No NAT address mapping is required if the two devices are in external networks and the Network Security appliance initiates the connection.