Forum Discussion
How to full-cone nat on CGNAT
Hi, How to config full-cone nat on CGNAT ?
1 Reply
- VernonWells
Employee
Full-cone NAT has two ramifications: any packet from iIP:iPort is mapped to the same eIP:ePort, and any inbound flow/connection to eIP:ePort is forwarded to iIP:iPort. The first ramification is a natural side-effect of how the BIG-IP maps internal clients to a translation address+port. The second is accomplished by enabling inbound connections:
Though the BIG-IP documentation about this is generally spare, F5 refers to this as Endpoint-Independent Filtering.
So, the short answer is: enable inbound connections as described in SOL14823.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
