Network Address Translation

Slides:



Advertisements
Similar presentations
1 Network Address Translation (NAT) Relates to Lab 7. Module about private networks and NAT.
Advertisements

CST Computer Networks NAT CST 415 4/10/2017 CST Computer Networks.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Implementing IP Addressing Services Accessing the WAN – Chapter 7.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 W. Schulte Chapter 5: Network Address Translation for IPv4  Connecting.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Lecture15: Network Address Translation for IPv4 Connecting Networks.
1 Comnet 2010 Communication Networks Recitation 7 Lookups & NAT.
1 Network Address Translation (NAT) Relates to Lab 7. Module about private networks and NAT.
Chapter 6 Network Address Translation (NAT). Network Address Translation  Modification of source or destination IP address  Needed by networks using.
Sybex CCNA Chapter 11: Network Address Translation Instructor & Todd Lammle.
Subnetting.
CCNA Guide to Cisco Networking Fundamentals Fourth Edition Chapter 9 Network Services.
Lecture Week 7 Implementing IP Addressing Services.
1 Network Address Translation (NAT) Relates to Lab 7. Module about private networks and NAT.
Sybex CCENT Chapter 13: Network Address Translation Instructor & Todd Lammle.
Network Address Translation (NAT) CS-480b Dick Steflik.
CECS 474 Computer Network Interoperability Notes for Douglas E. Comer, Computer Networks and Internets (5 th Edition) Tracy Bradley Maples, Ph.D. Computer.
CN2668 Routers and Switches Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Network Address Translation
COMS W COMS W Lecture 8. NAT, DHCP & Firewalls.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 4 v3.0 Module 1 Scaling IP Addresses.
NAT (Network Address Translation) Natting means "Translation of private IP address into public IP address ". In order to communicate with internet we must.
9/11/2015Home Networking1 Bob.test Have Road Runner Unhappy about reports of constant probes of machines Policy decision –I want to prevent unauthorized.
Page 1 NAT & VPN Lecture 8 Hassan Shuja 05/02/2006.
1 NAT Network Address Translation Motivation for NAT To solve the insufficient problem of IP addresses IPv6 –All software and hardware need to be updated.
Introduction to Network Address Translation
CS 540 Computer Networks II Sandy Wang
Implementing IP Addressing Services Accessing the WAN – Chapter 7.
Network Address Translations Project no. : 12 Prof. Edmund Gean Presented by DhruvaPatel( ) Sweta Patel( ) Rushika Patel ( ) Guided.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Planning the Addressing Structure Working at a Small-to-Medium Business.
Private Network Addresses IP addresses in a private network can be assigned arbitrarily. – Not registered and not guaranteed to be globally unique Generally,
NAT and PAT. Topics RFCs 1597(obs by 1918), 1631,1917, 1918 & 1797 Network Address Translation – Static and Dynamic Port Address Translation Issues with.
1 Network Address Translation (NAT) and Dynamic Host Configuration Protocol (DHCP) Relates to Lab 7. Module about private networks and NAT.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 11: Network Address Translation for IPv4 Routing And Switching.
Configuring NAT and PAT Chapter 18 powered by DJ 1.
NAT & PAT Network Address Translation Port Address Translation.
IP Addressing.
NAT/PAT by S K SATAPATHY
Click to edit Master subtitle style Chapter 8: IP Subnetting, Troubleshooting and Introduction to NAT Instructor:
CCNA4-1 Chapter 7-1 IP Addressing Services Scaling Networks With Network Address Translation (NAT)
CCNA4-1 Chapter 7-1 NAT Chapter 11 Routing and Switching (CCNA2)
CS 3700 Networks and Distributed Systems
Planning the Addressing Structure
4.3 Network Layer Logical Addressing
NAT : Network Address Translation
Chapter 13 Network Address Translation
Network Address Translation (NAT)
Instructor Materials Chapter 9: NAT for IPv4
CS 3700 Networks and Distributed Systems
NAT / PAT.
Network Address Translation (NAT)
Routing and Switching Essentials v6.0
Introducing To Networking
NAT , Device Discovery Chapter 9 , chapter 10.
NET323 D: Network Protocols
New Solutions For Scaling The Internet Address Space
Implementing IP Addressing Services
CIS 82 Routing Protocols and Concepts Chapter 11 NAT
Routing and Switching Essentials v6.0
NAT / PAT.
Cabrillo College Building Cisco Remote Access Network
CS 3700 Networks and Distributed Systems
Instructor Materials Chapter 9: NAT for IPv4
NET323 D: Network Protocols
Planning the Addressing Structure
Implementing IP Addressing Services
Planning the Addressing Structure
Chapter 11: Network Address Translation for IPv4
Prepared by :Adeel Ahmad
Network Address Translation (NAT)
Sybex CCNA Chapter 11: Network Address Translation.
Presentation transcript:

Network Address Translation Presented by Varsha Honde

NAT NAT maps Private IPs to Public IPs. A short term solution to the problem of the depletion of IP addresses It is required because of shortage of IPv4 Address. Whatever connects directly into Internet must have public (globally unique) IP address So Private IP addresses can be used within a private network Three address ranges are reserved for private usage 10.0.0.0/8 172.16.0.0/16 to 172.31.0.0/16 192.168.0.0/24 to 192.168.255.0/24 A private IP is mapped to a Public IP, when the machine has to access the Internet

NAT NAT is a router function where IP addresses (and possibly port numbers) of IP datagram's are replaced at the boundary of a private network NAT is a method that enables hosts on private networks to communicate with hosts on the Internet. NAT is run on routers that connect private networks to the public Internet, to replace the IP address-port pair of an IP packet with another IP address-port pair.

List of Situations when NAT is used: When you need to connect to the Internet and your hosts don’t have globally unique IP addresses. When you’ve changed to a new ISP that requires you to renumber your network. When you need to merge two intranets with duplicate addresses

NAT Names Names Meaning Inside Local Source host inside address before translation typically an RFC 1918 address Outside Local Address from which source host is known on the Internet. This is usually the address of the router interface connected to ISP—the actual Internet address. Inside Global Source host address used after translation to get onto the Internet. This is also the actual Internet address. Outside Global Address of outside destination host. The real Internet address.

Translation Modes Dynamic Translation (IP Masquerading) Static Translation Load Balancing Translation Network Redundancy Translation

Dynamic Translation (IP Masquerading) Network Address and Port Translation (NAPT) Map an unregistered IP address to a registered IP address from out of a pool of registered IP addresses. large number of internal users share a single external address. NAT only prevents external hosts from making connections to internal hosts.

Static Translation Allow one-to-one mapping between local and global addresses. A block external addresses are translated to a same size block of internal addresses Firewall just does a simple translation of each address. Port forwarding - map a specific port to come through the Firewall rather than all ports. Useful to expose a specific service on the internal network to the public network

Load Balancing Translation Maps multiple unregistered IP addresses to a single registered IP address (many-to-one) by using different source ports. Port Address Translation (PAT) which is also commonly referred to as NAT Overload. PAT allows you to permit thousands of users to connect to the Internet using only one real global IP address. Only works for stateless protocols (like HTTP)

Network Redundancy Translation Multiple internet connections are attached to a NAT Firewall that it chooses. Uses based on bandwidth, congestion and availability. Can be used to provide automatic fail-over of servers or load balancing. Firewall is connected to multiple ISP with a masquerade for each ISP and chooses which ISP to use based on client load kind of like reverse load balancing Adead ISP will be treated as a fully loaded one and the client will be routed through another ISP.

Pooling of IP Addresses Scenario: Corporate network has many hosts but only a small number of public IP addresses.

Pooling of IP Addresses NAT solution: Corporate network is managed with a private address space. NAT device, located at the boundary between the corporate network and the public Internet, manages a pool of public IP addresses. When a host from the corporate network sends an IP datagram to a host in the public Internet, the NAT device picks a public IP address from the address pool, and binds this address to the private address of the host.

Supporting Migration between Network Service Providers Scenario: In CIDR, the IP addresses in a corporate network are obtained from the service provider. Changing the service provider requires changing all IP addresses in the network.

Supporting Migration between Network Service Providers NAT solution: Assign private addresses to the hosts of the corporate network. NAT device has static address translation entries which bind the private address of a host to the public address. Migration to a new network service provider merely requires an update of the NAT device. The migration is not noticeable to the hosts on the network. Note: The difference to the use of NAT with IP address pooling is that the mapping of public and private IP addresses is static.

IP Masquerading Scenario: Single public IP address is mapped to multiple hosts in a private network.

IP Masquerading NAT solution: Assign private addresses to the hosts of the corporate network. NAT device modifies the port numbers for outgoing traffic.

Load Balancing of Servers Scenario: Balance the load on a set of identical servers, which are accessible from a single IP address

Load Balancing of Servers NAT solution: Here, the servers are assigned private addresses. NAT device acts as a proxy for requests to the server from the public network. The NAT device changes the destination IP address of arriving packets to one of the private addresses for a server. A sensible strategy for balancing the load of the servers is to assign the addresses of the servers in a round-robin fashion.

NAT Advantages Increases flexibility when connecting to the Internet. Eliminates address renumbering as a network evolves. Remedies address overlap events. Conserves legally registered addresses.

Services that NAT has problems with H.323, CUSeeMe, VDO Live – video teleconferencing applications Xing – Requires a back channel Rshell – used to execute command on remote Unix machine – back channel IRC – Internet Relay Chat – requires a back channel PPTP – Point-to-Point Tunneling Protocol SQLNet2 – Oracle Database Networking Services FTP – Must be RFC-1631 compliant to work ICMP – sometimes embeds the packed address info in the ICMP message IPSec – used for many VPNs IKE – Internet Key Exchange Protocol ESP – IP Encapsulating Security Payload

NAT Applications Hardware and software firewalls. Routers. Proxy servers RAS server that is a simple router/firewall