Router Configuration for Home Security: Forward your Ports Presenter: Steve Harris SCTE Director Advanced Network Technologies Program Development
© 2011 by the SCTE2Router Configuration for Home Security LINK
Agenda Describe the relationship of TCP/IP and TCP and UDP ports Explain the role and function of a NAT enabled GWR in the customer premises network Demonstrate the configuration of an IP surveillance camera and port forwarding © 2011 by the SCTE3Router Configuration for Home Security
Introduction
Why? HDTV / 3DTV STB / DVR / PVR eMTA Wireless GWR Printer Cordless Analog Phone Desktop PC Smartphone Laptop Fax Internet remote devices LAN IP x/24 WAN IP © 2011 by the SCTE5Router Configuration for Home Security
What is TCP/IP? © 2011 by the SCTERouter Configuration for Home Security6
TCP/IP Ubiquitous Communication Protocol Suite of protocols (65,535) Client / Server model Internet Cable Operator Cable Operator © 2011 by the SCTE7Router Configuration for Home Security
TCP/IP Internet devices have at least one IP address – e.g., TCP/IP defined 2 16 ports (65,535) per IP address Devices send data using port number from source to destination © 2011 by the SCTE8Router Configuration for Home Security
What is a port (socket)? TCP/IP uses an abstract destination point called a protocol port. Ports are identified by a positive integer value, e.g. 80. Operating Systems provide some mechanism that processes use to specify a port DNS port SSL port TCP/IP 80 HTTP port GWR CM/eMTA © 2011 by the SCTE9Router Configuration for Home Security
Port Numbers Well-known ports 0 – 1023 HTTP, FTP, SSL, Telnet, SSH, DNS, etc… Dynamically or Private Ports 49,152 to Registered ports or vendor-specific applications 1024 to 49,151 0 = no port has been allocated © 2011 by the SCTE10Router Configuration for Home Security
Port Names DNS = 53 HTTP = 80 © 2011 by the SCTE11Router Configuration for Home Security
What is the OSI model? © 2011 by the SCTERouter Configuration for Home Security12
Network Model RF DOCSIS / PacketCable ™ IPv4/6 TCP UDP Layers ICMP DATA Port Numbers Protocol Numbers © 2011 by the SCTE13Router Configuration for Home Security
User Datagram Protocol Connectionless Unreliable Datagram Delivery Video traffic Source PortDestination Port LengthChecksum Data © 2011 by the SCTE14Router Configuration for Home Security
Transmission Control Protocol Connection- oriented Reliable Full-duplex Byte-Stream Voice & data traffic Destination Port TCP Options (if any) Data Source Port Sequence Number Acknowledgement Number offsetReser.TCP FlagsWindow ChecksumUrgent Pointer © 2011 by the SCTE15Router Configuration for Home Security
UDPTCP Common Ports Internet Application Layer Transport Layer © 2011 by the SCTE16Router Configuration for Home Security
Network Address Translation Port Address Translation
What is NAT & PAT? © 2011 by the SCTERouter Configuration for Home Security18
NAT © 2011 by the SCTERouter Configuration for Home Security iPad Inside Outside #29225 Internet Inside Local IP Address Inside Global IP Address # # #29227 scte.org private side public Remote PC CM
NAT © 2011 by the SCTE20Router Configuration for Home Security
Example
Connect Surveillance Camera © 2011 by the SCTERouter Configuration for Home Security22 GWR eMTA LAN IP x/
Connect Surveillance Camera © 2011 by the SCTERouter Configuration for Home Security23 GWR eMTA LAN IP x/ Wireless Setup Page
DHCP Client Table © 2011 by the SCTERouter Configuration for Home Security24
Wireless Setup XXXXXXX © 2011 by the SCTE25Router Configuration for Home Security
Surveillance Camera is Wireless © 2011 by the SCTERouter Configuration for Home Security26 GWR eMTA LAN IP x/ Wireless Setup Page
DHCP or Static? © 2011 by the SCTERouter Configuration for Home Security27
GWR Config © 2011 by the SCTERouter Configuration for Home Security28 GWR eMTA LAN IP x/ GWR Config
Port Forwarding © 2011 by the SCTE29Router Configuration for Home Security
Port Range Forwarding © 2011 by the SCTE30Router Configuration for Home Security
Port Triggering Port triggering is a configuration option on a GWR with NAT to allows a host to dynamically and automatically forward a specific port back to itself. © 2011 by the SCTE31Router Configuration for Home Security
What the inside global IP (outside)? © 2011 by the SCTERouter Configuration for Home Security32
HDTV / 3DTV STB / DVR / PVR eMTA Broadband Connection Wireless GWR Printer Cordless Analog Phone Desktop PC Smartphone Laptop Fax Let’s test it!
SMC © 2011 by the SCTERouter Configuration for Home Security to are static local inside IP address TCP / UDP Port 10
NETGEAR © 2011 by the SCTERouter Configuration for Home Security35
You try © 2011 by the SCTERouter Configuration for Home Security36 Internet Camera Camera Camera
Summary Described the relationship of TCP/IP and TCP and UDP ports Explained the role and function of a NAT enabled GWR in the customer premises network Demonstrated the configuration of an IP surveillance camera and port forwarding © 2011 by the SCTE37Router Configuration for Home Security