Port Restricted Cone NAT

The port restricted cone NAT restricts an external host‘s ability to initiate a packet exchange with the internal client by both IP address and port. The restricted cone NAT method requires that the internal client has already initiated a packet exchange with the external host port that passed the protocol and port criteria listed in the access list assigned to the port restricted cone NAT configuration. Once the internal client initiates a packet exchange with the external host, that host can only initiate a packet exchange with the internal client using the port the internal client sent the initial packet flow to. The external server can initiate an exchange using any protocol.

Port Restricted Cone NAT shows an example of port restricted cone NAT.

Click to expand in new window
Port Restricted Cone NAT
Graphics/NatPortRestrictedCone1.png