ip nat translation port-timeout -- WHICH port?

ip nat translation port-timeout -- WHICH port?

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
ip nat translation port-timeout -- WHICH port? Jon.R.Kibler 07-30-2008
Posted by on July 30, 2008, 4:08 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

A question about port-timeout: Which port does this refer to, the
inside or outside port.

For example:
ip nat translation port-timeout udp 123 30

Is this the 123/udp on the inside or outside network?

THANKS!
Jon K

Pure Networks
Posted by News Reader on July 30, 2008, 6:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Jon.R.Kibler@gmail.com wrote:
> Hi,
>
> A question about port-timeout: Which port does this refer to, the
> inside or outside port.
>
> For example:
> ip nat translation port-timeout udp 123 30
>
> Is this the 123/udp on the inside or outside network?
>
> THANKS!
> Jon K

Opinion:

I suspect that it would influence any translation referencing the port
number (inside global, inside local, outside local, outside global).

Consider HTTP translations rather than NTP, because the client and
server ports would differ with HTTP.

Compare a translation for an outbound connection to an Internet-based
Web server, and another translation for an inbound connection to a web
server within your organization.

In one instance it is the outside local and outside global addresses
listening on port 80, and for the other it is the inside global and
inside local addresses listening on port 80.

Presumably, you would expect/want both translations to be influenced by
your NAT translation port-timeout configuration. If not, you'd have to
settle for a generic TCP timeout, or configure a timeout for all
possible client ports for one of the two scenarios.

Once connection initiation triggers the translation, I would expect
traffic in either direction would reset the timer.

Best Regards,
News Reader

Similar ThreadsPosted
Port translation with PIX 506E January 23, 2006, 9:10 pm
PIX 515 Rejection happens before port translation ??? November 27, 2006, 9:20 am
port translation happens after packet is rejected ??? November 27, 2006, 7:46 am
Re: Cisco VPN behind a nat router with port translation. February 18, 2007, 2:03 pm
Re: PIX - "No translation group found for udp src outside..." port 137 July 24, 2007, 1:27 pm
PIX - "No translation group found for udp src outside..." port 137 July 24, 2007, 6:41 am
Of Translation and ACL August 13, 2004, 10:37 am
VPN with NAT translation June 24, 2005, 6:33 am
Nat Translation June 2, 2006, 1:56 pm
IP translation - It's possible? May 8, 2007, 4:53 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map