< Home

Configuring DS-Lite NO-NAT

This section describes how to configure DS-Lite NO-NAT.

Prerequisites

The following configurations must be complete before configuring an interzone NAT policy:

Exempting DS-Lite Packets from NAT

When the CGN device receives packets from the CPE, NAT shall not be performed on the packets in certain scenarios. As shown in Figure 1, public network users in area A need to access the server in area B, and an IPSec tunnel is established on the routing device. The router does not support NAT traversal. If the CGN device performs NAT on received packets, services are interrupted. Therefore, the CGN device is required to perform only DS-Lite tunnel decapsulation but not NAT on the received packets.

Figure 1 Public network users in area A accessing the public server in area B over the IPv6 network

Procedure

  1. Configure the device to forward DS-Lite packets that do not match the NAT policy.
    1. Run the system-view command to access the system view.
    2. Run the tunnel ds-lite no-nat action forward command to configure the device to forward DS-Lite packets that do not match the NAT policy.
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >