20.01.2014 Views

Lectures notes for 2010 - KTH

Lectures notes for 2010 - KTH

Lectures notes for 2010 - KTH

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Network Address Translation<br />

exterior<br />

interior<br />

Figure 9: Example of a Firewall with NAT<br />

NAT maps IP addresses on the inside to one or more addresses on the outside and<br />

vice versa. See RFC 3022 [29] and RFC2766 [30]<br />

Advantages:<br />

Internet<br />

y.y.y.y (.. z.z.z.z)<br />

(provided by the ISP)<br />

✔ save IPv4 addresses<br />

✔ hides internal node structure from outside<br />

nodes<br />

✔ the intranet does not have to be renumbered<br />

when you connect to another ISP<br />

Proxy Server<br />

manually enabled bypass<br />

NAT<br />

Disadvantage<br />

Intranet<br />

192.168.0.x<br />

192.168.0.1<br />

✘ Un<strong>for</strong>tunately this breaks many<br />

services because they use an IP<br />

address inside the their data.<br />

Maguire Network Address Translation 12: 23 of 30<br />

maguire@kth.se <strong>2010</strong>.03.21 Internetworking/Internetteknik

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!