CISCO NETWORKING ACADEMY Chabot College ELEC 99.08 Network Address Translation.

Slides:



Advertisements
Similar presentations
Internet Protocol How does information get sent from one device to another across a WAN?
Advertisements

© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
CISCO NETWORKING ACADEMY Chabot College ELEC Address Resolution Protocol.
IP Masquerading Homes and Businesses: When you only have one IP but you have LOTS of machines.
Security Firewall Firewall design principle. Firewall Characteristics.
Information Networking Security and Assurance Lab National Chung Cheng University Private IP(RFC1918) The Internet Assigned Numbers Authority (IANA) has.
IP Address 1. 2 Network layer r Network layer protocols in every host, router r Router examines IP address field in all IP datagrams passing through it.
Lesson 18-Internet Architecture. Overview Internet services. Develop a communications architecture. Design a demilitarized zone. Understand network address.
NAT: Network Address Translation local network (e.g., home network) /24 rest of Internet Datagrams.
Understanding IP Addressing Chuck Semeria Presented by Benyuan Liu for Internet Routing Seminar Sep 19, 2000.
CSE5803 Advanced Internet Protocols and Applications (7) Introduction The IP addressing scheme discussed in Chapter 2 are classful and can be summarised.
M. Dahshan - TCOM52721 TCOM 5272 Telecomm Lab Dr. Mostafa Dahshan OU-Tulsa 4W 2 nd floor
IP Address 1. 2 Network layer r Network layer protocols in every host, router r Router examines IP address field in all IP datagrams passing through it.
Firewalls1 Firewalls Mert Özarar Bilkent University, Turkey
Subnetting.
CCNA Guide to Cisco Networking Fundamentals Fourth Edition Chapter 9 Network Services.
Andrew Smith 1 NAT and DHCP ( Network Address Translation and Dynamic Host Configuration Protocol )
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Network Addressing Networking for Home and Small Businesses – Chapter 5.
Chapter 8 PIX Firewall. Adaptive Security Algorithm (ASA)  Used by Cisco PIX Firewall  Keeps track of connections originating from the protected inside.
4: Addressing Working At A Small-to-Medium Business or ISP.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 4: Addressing in an Enterprise Network Introducing Routing and Switching in the.
CN2668 Routers and Switches Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
CISCO NETWORKING ACADEMY Chabot College ELEC Application Layer Puzzles.
Network Address Translation
9/11/2015Home Networking1 Bob.test Have Road Runner Unhappy about reports of constant probes of machines Policy decision –I want to prevent unauthorized.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Addressing in an Enterprise Network Introducing Routing and Switching in the.
Introduction to Network Address Translation
Chabot College ELEC Network Devices.
1 Chapter 7: NAT in Internet and Intranet Designs Designs That Include NAT Essential NAT Design Concepts Data Protection in NAT Designs NAT Design Optimization.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Addressing in an Enterprise Network Introducing Routing and Switching in the.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 4: Addressing in an Enterprise Network Introducing Routing and Switching in the.
Addressing IP v4 W.Lilakiatsakun. Anatomy of IPv4 (1) Dotted Decimal Address Network Address Host Address.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Planning the Addressing Structure Working at a Small-to-Medium Business.
Private Network Addresses IP addresses in a private network can be assigned arbitrarily. – Not registered and not guaranteed to be globally unique Generally,
Network Security1 – Chapter 6 – NAT and Security Network Address Translation (NAT) is useful: –Hide internal private IP addresses –Conserve routable IP.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Implementing IP Addressing Services Accessing the WAN – Chapter 7.
Network Address Translation External/ Internal/. OVERLOADING In Overloading, each computer on the private network is translated to the same IP address;
Chapter 9 Cisco IOS Firewall. IOS Firewall  Stateful packet-filter firewall that runs on a router  Provides firewall capabilities and normal routing.
CISCO NETWORKING ACADEMY Chabot College ELEC Windows IP Configuration Information.
IP Addressing.
Section #7: Getting Data from Point A to Point B.
NAT/PAT by S K SATAPATHY
CCNA Discovery Semester 3 Addressing in an Enterprise Network Chapter 4 K. Martin.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Subnetting IP Networks.
Lecture#7: Subnetting IP Networks
Source NAT Configuration Example Alcatel-Lucent Security Products Configuration Example Series.
© 2001, Cisco Systems, Inc. CSPFA 2.0—5-1 Chapter 5 Cisco PIX Firewall Translations.
Planning the Addressing Structure
Chapter 05 Exam Review CCNA Discovery 01 – Computer and Network Fundamentals Presented by: Phillip Place Cisco Academy Instructor Lake Michigan College.
100% Exam Passing Guarantee & Money Back Assurance
Networking for Home and Small Businesses – Chapter 5
Lecture#7: Subnetting IP Networks
Instructor Materials Chapter 9: NAT for IPv4
IP Addressing - The Problem
– Chapter 6 – NAT and Security
Routing and Switching Essentials v6.0
Chabot College ELEC Why Subnet?.
Introducing To Networking
Chapter 9: Subnetting IP Networks
New Solutions For Scaling The Internet Address Space
Chapter 9: Subnetting IP Networks
Routing and Switching Essentials v6.0
NAT and Security Source: Ch. 6 of Malik
Instructor Materials Chapter 9: NAT for IPv4
Transport Layer Systems Firewalls and NAT
Planning the Addressing Structure
Planning the Addressing Structure
Chapter 11: Network Address Translation for IPv4
Networking for Home and Small Businesses – Chapter 5
Presentation transcript:

CISCO NETWORKING ACADEMY Chabot College ELEC Network Address Translation

CISCO NETWORKING ACADEMY Shortcomings of Subnetting: Waste (up to 50%) –Lots of addresses are unusable: first & last subnet first & last host in each subnet Rigidity –Subnet structure is inflexible same size for every subnet subnet with largest no. of hosts determines size for all

CISCO NETWORKING ACADEMY Case Study: 4CNet IP Address Allocation to Chabot-Las Positas Algorithm: #hosts/254 = #class Cs Fails to consider network structure. Subnets needed for: –Broacast control –WAN links –Access policy enforcement

CISCO NETWORKING ACADEMY Case Study: 4CNet IP Address Allocation to Chabot-Las Positas Can we afford the waste & rigidity of subnetting? YES, if we run NAT & a large private address space.

CISCO NETWORKING ACADEMY Network Address Translation (NAT) Private address space inside network 4CNet-assigned addresses outside network Translation performed by Cisco PIX (Private-Internet Exchange) (Can also be performed by a router.)

CISCO NETWORKING ACADEMY How NAT works...

CISCO NETWORKING ACADEMY Default Translation The PIX assigns a single address to all traffic sent to the internet. The PIX uses TCP sequence numbers to map the returning traffic from established sessions to internal host addresses. Supports > 16,000 simultaneous sessions.

CISCO NETWORKING ACADEMY Address Mapping Internal hosts can be mapped to both internal (private) and external IP addresses:

CISCO NETWORKING ACADEMY What problems does NAT solve? Allows a huge address space for your net. Allows creation of many subnets with many hosts. (e.g. Class B network subnetted ). Address waste doesn’t matter. Rigidity doesn’t matter (subnets can be oversized to allow for growth) Allows flexible access policies and firewalling.

CISCO NETWORKING ACADEMY What problems does NAT solve? …and you’ll never have to renumber your network again.

CISCO NETWORKING ACADEMY What tradeoffs result? Capital cost of the box. Single point of failure in connection to internet. Dual DNS required… But this is also an advantage: lets you decide what the world gets to learn about your internal network.

CISCO NETWORKING ACADEMY Dual DNS