Setting Netopia Cayman to operate in SUA Mode I have a requirement for a client to turn off NATting on a Netopia Device in order to "mask" the address that presents to the internet.
Essentially I want to place a firewall device internally with one of a block of IP addresses assigned to it that will show as being the public address.
The client has a block of 8 addresses - one of which is autonegotiated from Eircom. Current Scenario:
Zyxel Prestige 645 router in SUA mode on the outside.
SBS premium (ISA) with dual NIC configuration on the inside.
Range of addresses 83.x.y.64 - 83.x.y.71
Address that is received by the existing DSL device is 83.x.y.65.
External address of ISA is 83.x.y.70. This address is how he presents to the internet. Objectives:
1) Place a Netopia device at the "outside" of the network, configured to run with NAT disabled. This will receive the auto negotiated 83.x.y.65 address. It is my understanding that whilst NAT is disabled, the "next device in" should be visble to internet traffic. (Please feel free to correct me if I'm wrong)
2) Insert a Zyxel ZyWall 35 UTM device configured with the 83.x.y.70 as its WAN interface, and a non routable address on its LAN interface. This should then present to the internet on this address.
3) Enable NATting for specific ports and services to the outside of the ISA Server - this address will be changed to a non routable address aswell.
The Zywall device will not talk to the existing Prestige device due to port speed errors, hence the reason for removing the Prestige. I don't necessarily want to put undue expense on the customer (as it happens I have an invetory of Netopia 3347 devices that I am happy to donate to the client)
Anyone ever had to do this before? How simple or difficult is the reconfiguration of the Netopia to disable NAT?
My apologies for the length of post - please post back suggestions. |