The stateful NAT64 feature enables communication between IPv6 clients and IPv4 servers through IPv6 to IPv4 packet translation, and vice versa, while maintaining session information on the NetScaler appliance.
A stateful NAT64 configuration on the NetScaler appliance has the following components:
-
NAT64 rule— An entry consisting of an ACL6 rule and a netprofile, which consists of a pool of NetScaler owned SNIP Addresses.
-
NAT64 IPv6 Prefix— A global IPv6 prefix of length 96 bits (128-32=96) configured on the appliance. Note: Currently the NetScaler appliance supports only one prefix to be used commonly with all NAT 64 rules.
The NetScaler appliance considers an incoming IPv6 packet for NAT64 translation when all of the following conditions are met:
When an IPv6 request packet received by the NetScaler appliance matches an ACL6 defined in a NAT64 rule and the destination IP of the packet matches the NAT64 IPv6 prefix, the NetScaler appliance considers the IPv6 packet for translation.
The appliance translates this IPv6 packet to an IPv4 packet with a source IP address matching one of the IP address bound to the netprofile defined in the NAT64 rule, and a destination IP address consisting of the last 32 bits of the destination IPv6 address of the IPv6 request packet. The NetScaler appliance creates a NAT64 session for this particular flow and forwards the packet to the IPv4 server. Subsequent responses from the IPv4 server and requests from the IPv6 client are translated accordingly by the appliance, on the basis of information in the particular NAT64 session.
Consider an example in which an enterprise hosts site www.example.com on server S1, which has an IPv4 address. To enable communication between IPv6 clients and IPv4 server S1, NetScaler appliance NS1 is deployed with a stateful NAT64 configuration that includes a NAT64 rule and a NAT64 prefix. A mapped IPv6 address of server S1 is formed by concatenating the NAT64 IPv6 prefix
and the IPv4 source address
. This mapped IPv6 address is then manually configured in the DNS servers. The IPv6 clients get the mapped IPv6 address from the DNS servers to communicate withIPv4 server S1.
nat64
Following is the traffic flow in this example:
-
IPv6 client CL1 sends a request packet to Map-Sevr-IPv6 (2001:DB8:300::192.0.2.60) address.
-
The NetScaler appliance receives the request packet. If the request packet matches the ACL6 defined in the NAT64 rule, and the destination IP address of the packet matches the NAT64 IPv6 prefix, the NetScaler considers the IPv6 packet for translation.
-
The appliance creates a translated IPv4 request packet with:
-
Destination IP address field containing the NAT64 prefix stripped from the destination address of the IPv6 request (Sevr_IPv4 = 192.0.2.60)
-
Source IP address field containing one of the IPv4 address bound to Netprofile-1(in this case, 192.0.2.100)
-
The NetScaler appliance creates a NAT64 session for this flow and sends the translated IPv4 request to server S1.
-
IPv64 server S1 responds by sending an IPv4 packet to the NetScaler appliance with:
-
The appliance receives the IPv4 response packet, searches all the session entries, and finds that the IPv6 response packet matches the NAT64 session entry created in step 4. The appliance considers the IPv4 packet for translation.
-
The appliance creates a translated IPv6 response packet with:
-
The appliance sends the translated IPv6 response to client CL1.