Installing and configuring NAT (Network Address Translation).

(Last modified: 07Jul2005)

This document (10011265) is provided subject to the disclaimer at the end of this document.

goal

Installing and configuring NAT (Network Address Translation).

fact

Formally TID # 2933795

Novell NetWare 4.11

Novell IntraNetWare 4.11

Novell BorderManager FastCache 2.1

Novell BorderManager 2.1

Novell NetWare MultiProtocol Router

Novell GroupWise 5.2

Novell GroupWise 5.5

Novell NetWare for Small Business 4.11

Novell NetWare for Small Business 4.2

Novell NetWare 5.0

Novell BorderManager 3.0

Novell BorderManager 3.5

fix

1.  Read the March 1998 AppNotes on "Network Address Translator (NAT) Theory and Troubleshooting."
HTML version: http://support.novell.com/techcenter/articles/ana19980304.html

Review the BorderManager Online Documentation for NAT.
     A. General BorderManager Online Documentation:
http://WWW.NOVELL.COM/documentation/en/bordermgr/index.html
     B. Concepts of NAT:
http://www.novell.com/documentation/en/bordermgr/nias41/rtcn_enu/docmodul/ch2s21.htm
     C. Configuring NAT:
http://WWW.NOVELL.COM/documentation/en/bordermgr/nias41/rtcf_enu/docmodul/ch11s14.htm
     D. Concepts of TCP/IP Multihoming:
http://WWW.NOVELL.COM/documentation/en/bordermgr/nias41/rtcn_enu/docmodul/ch2s20.htm#FB15634

3. Hardware requirements: See SUPPORT.NOVELL.COM  TID # 2930436.

4.  Make sure all public and private TCP/IP addresses and net masks are correct in the "bindings" area.

5.  Add all secondary IP addresses needed for NAT "static" modes:

6. What are the three NAT modes used for and when should they be used?
     A.  Dynamic only mode:
     B.  Static only mode:
     C.  Dynamic and Static mode:
See  Concepts of NAT: http://doc1.provo.novell.com/English/bordermgr/nias41/rtcn_enu/docmodul/ch2s21.htm

7.
When ever NAT is enabled in either "Dynamic mode" or "Dynamic and Static mode", the following command should be added to the SYS:\SYSTEM\AUTOEXEC.NCF file: See TID # 2929345 : set Network Address Translation SET NAT DYNAMIC MODE TO PASS THRU=ON

8. All workstations, clients, gateways, hosts, servers, etc., that will be going through NAT either through Static mode or
Dynamic mode, MUST have their "default gateway", "default router", "static route" pointing to the IP address of the NIC in
the BorderManager server that they are connected to. Use the following steps to configure the "default static route" on systems on the private side:
     A. NetWare Servers: See TID # 2911404 - Setting a Default Lan Static Route
     B. Workstations and other servers:  See your TCP/IP Network Configuration area

9. All workstations, clients, gateways, hosts, servers, etc., that will be going through NAT either through Static mode or
Dynamic mode, MUST have their "DNS" Domain Name Service configured locally and pointing to the either a local DNS or a
DNS server out on the Internet or at your ISP. Use the following steps to configure the "DNS Resolver" on
systems on the private side:
     A. BorderManager Servers: See "Configuring the DNS Resolver" in the Online Docs. http://WWW.NOVELL.COM/documentation/en/bordermgr/nias41/rtcn_enu/docmodul/ch2s20.htm#FB14798
     B.
NetWare Servers: See SUPPORT.NOVELL.COM TID # 2912130 -- SYS:\ETC\RESOLV.CFG
     C. Workstations and other servers:  See your TCP/IP Network Configuration area
  
10. When ever you change the NAT modes, like from Dynamic to static, or Static to dynamic, or dynamic to dynamic and static, the BorderManager server MUST be "downed" and "restarted", or the TCPIP.NLM unloaded, otherwise the NAT/TCPIP tables don't get changed.

11.  Filtering / Firewall issues with NAT:  See TID SUPPORT.NOVELL.COM TID # 2932576 -- Filtering Exceptions Summary

12.  Troubleshooting:
A. See SUPPORT.NOVELL.COM TID # 2930101 -- NAT doesn't seem to be working for some workstations.
B. See SUPPORT.NOVELL.COM TID # 2930569 -- Static and Dynamic not working correctly
C. See SUPPORT.NOVELL.COM TID # 2932377 -- Proxy not working and NAT in Static only mode
D. See SUPPORT.NOVELL.COM TID # 2932337 -- ABEND in TCP/IP when NAT is enabled

NOTE:  NAT should only ever be enabled on the Public interface, never on the Private interface and never on both interfaces..

document

Document Title: Installing and configuring NAT (Network Address Translation).
Document ID: 10011265
Solution ID: 4.0.1390981.2202743
Creation Date: 24Jun1999
Modified Date: 07Jul2005
Novell Product Class:Connectivity Products
Groupware
Management Products
NetWare
Novell BorderManager Services
Web Services

disclaimer

The Origin of this information may be internal or external to Novell. Novell makes all reasonable efforts to verify this information. However, the information provided in this document is for your information only. Novell makes no explicit or implied claims to the validity of this information.
Any trademarks referenced in this document are the property of their respective owners. Consult your product manuals for complete trademark information.