+--------------------------+ | | | FW Cluster | | tagged VLAN | - | 24 IP 10.100.32.249/29 | | | - +--------------------------+ - | | | | | | | +----------+-------------+ | | + | Router Provider | | 10.100.32.254/29 | | | | | +---------+--------------+ | | | | | | | | +---------------------------------------------------------------------+ | | | | | | | Standort IP Range 10.100.40.0/22 (DHCP) | | | | | | | | | | | | | +---------------------------------------------------------------------+
NAT reflection: When a client on the internal network tries to access another client, but using the external IP instead of the internal one (which would the most logical), NAT reflection can rewrite this request so that it uses the internal IP, in order to avoid taking a detour and applying rules meant for actual outside traffic.