DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
MultiNAT - Specifying Outgoing IPs
- pg_bennett
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 10
- Thank you received: 0
25 Jan 2011 21:50 #65856
by pg_bennett
MultiNAT - Specifying Outgoing IPs was created by pg_bennett
Hello,
I've been looking at Multinat as a solution to one of my problems, which I believe will work in conjunction with Open Ports.
Essentially I have a mail server, SBS server and an Avaya IP Office 500 which need to be addressed externally (specific ports)
One of the problems I have, is that I need to choose the external source IP for the SIP service, and the SMTP service - which is different to that of the standard NAT'ed IP.
This document (below) seems to suggest that I need to set up a DMZ Hosts (eg for the Avaya IPO or mail server).
"How do I fix a one-to-one IP Mapping for outgoing traffic"
http://www.draytek.co.uk/support/kb_vigor_multinat.html#fixmap
My question is: Won't this expose ALL incoming ports, rather than just the ports specified in the "Open Ports" section, therefore posing a security risk ?
I've been looking at Multinat as a solution to one of my problems, which I believe will work in conjunction with Open Ports.
Essentially I have a mail server, SBS server and an Avaya IP Office 500 which need to be addressed externally (specific ports)
One of the problems I have, is that I need to choose the external source IP for the SIP service, and the SMTP service - which is different to that of the standard NAT'ed IP.
This document (below) seems to suggest that I need to set up a DMZ Hosts (eg for the Avaya IPO or mail server).
"How do I fix a one-to-one IP Mapping for outgoing traffic"
My question is: Won't this expose ALL incoming ports, rather than just the ports specified in the "Open Ports" section, therefore posing a security risk ?
Please Log in or Create an account to join the conversation.
- voodle
- Offline
- Big Contributor
Less
More
- Posts: 1139
- Thank you received: 0
26 Jan 2011 00:43 #65858
by voodle
Replied by voodle on topic MultiNAT - Specifying Outgoing IPs
Yes it will, but the information mostly refers to the older models, on later routers such as the 2820 series, there's an option in the NAT menu for Address Mapping - this does the same thing as DMZ but doesn't forward traffic, just sets which WAN IP the traffic from the specified LAN IPs will come from.
You can then set up port forwards separately.
You can then set up port forwards separately.
Please Log in or Create an account to join the conversation.
- pg_bennett
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 10
- Thank you received: 0
27 Jan 2011 22:02 #65927
by pg_bennett
Replied by pg_bennett on topic MultiNAT - Specifying Outgoing IPs
Thanks for this. I noticed this option, but this makes sense now.
Please Log in or Create an account to join the conversation.
Moderators: Sami
Copyright © 2024 DrayTek