Installing and Configuring NAT

Network Address Translation (NAT) Review

In Routing and Remote Access Service (RRAS), NAT can be used to provide basic Internet connectivity for small offices or home offices. NAT translates IP addresses and associated TCP/UDP port numbers on the private network to public IP addresses which can be routed on the Internet. Through NAT, host computers are able to share a single publicly registered IP address to access the Internet. NAT also offers a number of security features which can be used to secure the resources on your private network. The NAT service is integrated with the router that changes the information of the originator in packets prior to them being forwarded to the Internet. NAT can be configured through a demand-dial interface where the connection is only established when the client specifically requests the connection; or through a persistent connection which is a permanent connection that remains open all the time.

RRAS IP packet filters can be used to restrict incoming or outgoing IP address ranges based on information in the IP header. You can configure and combine multiple filters to control network traffic. With NAT, you can configure inbound IP packet filters and outbound IP packet filters. When defining criteria for the packet filters, you can use whatever combination of IP header information.

You can also map external public IP addresses and ports to private IP addresses and ports so that internal private resources can be accessed by Internet users. You use a special port to map specific Internet users to resources within the private network. You can configure a NAT address mapping for each specific private network resource that Internet users are allowed to access. The NAT address pool feature can be utilized to allow VPN users and Internet users to access resources residing in the private network. The NAT server requests for one of the public IP addresses with a specific TCP/UDP port number to resources in the private network

Planning for NAT Installation

A Windows Server 2003 server configured with either of the following services can act as the NAT server:

A few factors that should be clarified before you install, and configure NAT are listed here:

Installing the NAT Service

The Windows Server 2003 NAT server can support the following services or components:

The NAT server should have the following components:

NAT is included with Windows Server 2003 RRAS. While RRAS is automatically installed when you install Windows Server 2003, it is not automatically enabled as well. To enable RRAS, you can use either of the following mechanisms:

Windows Server 2003 also provides the Routing and Remote Access Server Setup Wizard which can be used to perform both of the following functions:

How to add NAT as a routing protocol

  1. Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access management console.
  2. In the console tree, expand Routing And Remote Access, the Server, and then expand IP Routing.
  3. Select, and then right-click General and next click New Routing Protocol from the shortcut menu.
  4. The Select Routing Protocol dialog box opens
  5. Select Network Address Translation.
  6. Click OK.

How to install the NAT service using the Routing And Remote Access Server Setup Wizard

  1. Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access management console.
  2. In the left console pane, select the RRAS server that you want to work with.
  3. From the Action menu, click Configure and Enable Routing and Remote Access.
  4. The Routing and Remote Access Server Setup Wizard initiates.
  5. Click Next on the Routing and Remote Access Server Setup Wizard welcome page.
  6. On the Configuration page, select the Network Address Translation (NAT) option, and then click Next.
  7. On the NAT Internet Connection page, you have to select the connection method which NAT will use to connect to the Internet:
    • Use this public interface to connect to the Internet option.
    • Create a new demand-dial interface to the Internet option.
  8. If you want to enable NAT security, leave the Enable security on the selected interface by setting up Basic Firewall option selected. The option is enabled by default. Click Next.
  9. On the Ready to Apply Selections page, click Next.
  10. Click Finish.
  11. 1
  12. Click Yes to start the Routing and Remote Access service.

Configuring NAT

You can use the Routing and Remote Access management console to configure a number of settings for the NAT.

To access the various configuration options for NAT,

  1. Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access management console.
  2. In the left console tree, expand Routing And Remote Access, the Server, and then expand IP Routing.
  3. Select NAT/Basic Firewall.
  4. Click the Action menu, and then select Properties OR, right-click NAT/Basic Firewall and select Properties from the shortcut menu
  5. The Properties dialog box contains four tabs which can be used to configure settings for the NAT service.

The various settings available on the different tabs within the Properties dialog box are:

How to configure a new interface for NAT

  1. Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access management console.
  2. Locate NAT/Basic Firewall in the console tree.
  3. Right-click NAT/Basic Firewall and select New Interface from the shortcut menu.
  4. Specify the type of interface. Click OK.
  5. Next, select Public Interface Connected To The Internet, and then select Enable NAT On This Interface.
  6. If no firewall capabilities exist, select Enable A Basic Firewall On This Interface.
  7. If necessary, configure the desired inbound/outbound IP packet filters to restrict incoming or outgoing traffic.
  8. Add the address range obtained by the ISP in the Address Pool tab.
  9. Specify the services which Internet users can access.
  10. Accept the default settings on the ICMP tab.
  11. 1
  12. Click OK.

How to configure special ports to allow inbound connections

  1. Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access management console.
  2. Locate the interface that you want to configure.
  3. Right-click the interface and then select Properties from the shortcut menu.
  4. Click the Special Ports tab.
  5. Under Protocol, select TCP or UDP and then click the Add button.
  6. Enter the port number of the incoming traffic in Incoming Port.
  7. Select On This Address Pool Entry, and provide the public IP address of the incoming traffic.
  8. Enter the port number of the private network resource in Outgoing Port.
  9. Enter the private network resource's private IP address in Private Address.
  10. Click OK.

How to configure a NAT network application

  1. Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access management console.
  2. In the console tree, select the NAT server that you want to configure.
  3. Right-click the NAT server and then select Properties from the shortcut menu.
  4. Click the Translation tab.
  5. Click the Application button.
  6. When the Application dialog box opens, click the Add button.
  7. The Add Application dialog box opens.
  8. Specify the desired settings for the application.
  9. Click OK.

How to manage the NAT server

  1. Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access management console.
  2. In the console tree, select the NAT server that you want to manage.
  3. Right-click the NAT server and then select Properties from the shortcut menu.
  4. Click the IP tab to manage NAT address assignment.
  5. If you want to use an existing DHCP server for IP address assignment, click the Dynamic Host Configuration Protocol (DHCP) option.
  6. If you want to specify the NAT server for IP address assignment, select the Static address pool option.
  7. Next, use the Add, Edit and Remove buttons to specify the address range which the NAT server will use to assign IP addresses to clients.
  8. If you do not have an existing DNS servers or WINS server that can be used for name resolution, click the Enable broadcast name resolution option at the bottom of the IP tab.
  9. Click OK.

Troubleshooting NAT

The typical problems experienced with NAT are usually due to not meeting a number of NAT configuration requirements:



Top 5 Free Networking Tools

Bookmark Installing and Configuring NAT

Latest Blog Posts


English English GermanGerman SpanishSpanish FrenchFrench ItalianItalian PortuguesePortuguese RussianRussian DutchDutch
GreekGreek HindiHindi JapaneseJapanese KoreanKorean ChineseChinese Chinese (Simplified)Chinese (Simplified) ArabicArabic

Copyright 2009 Tech-FAQ. All rights reserved. Privacy Policy.