Port Address Translation
Novell Cool Solutions: Question & Answer
Q:
I need to open different ports on the same external address but to different servers inside. For example, port 21 from external AA to address Internal YY and port 80 External AA to Internal ZZ. Does anyone have a solution? A short-term fix would be to get the client more addresses, but they have grown rapidly over the past few years, and some boxes only need one port open.
A:
NBM does not support inbound PAT - only static 1-to-1 mappings are implemented. I've seen things done with the transparent proxy, but I really cannot recommend this route.
I can, however, recommend front-ending the BorderManager server with a
basic Linux box running iptables. I use this with excellent success to provide PAT facilities. You can also do cool things with free IDS components as well. I would still strongly recommend using NBM for its proxy and VPN facilities however, as these are way ahead of anything on Linux (yet...)
Or, check out Novell Secure Manager at:
http://www.novell.com/products/securitymanager
Novell Cool Solutions (corporate web communities) are produced by WebWise Solutions. www.webwiseone.com
