<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2481847082284475001</id><updated>2011-07-29T00:31:41.526-07:00</updated><title type='text'>stop for a min</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://iknewnot.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2481847082284475001/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://iknewnot.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Freeman</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2481847082284475001.post-8008401401530579919</id><published>2009-12-03T23:21:00.001-08:00</published><updated>2009-12-03T23:21:11.133-08:00</updated><title type='text'>Network Address translation</title><content type='html'>&lt;b&gt;What is NAT?&lt;/b&gt;&lt;br /&gt;Network Address Translation translates your local or private IP addresses to public IP addresses so you can communicate to with the internet world.&lt;br /&gt;&lt;b&gt;Why NAT?&lt;/b&gt; Because its expensive to buy public IP addresses to each and every computer in a network.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Types of NAT:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Static NAT:&lt;/b&gt; This is like one-to-one i.e. your one particular private ip address is always translated to one dedicated public ip address.&lt;br /&gt;&lt;b&gt;Dynamic NAT:&lt;/b&gt; This is like many-to-many. Your list of private ip addresses are translated to a pool of public addresses, a public ip dynamically picked from that pool for your private ip addresses.&lt;br /&gt;&lt;b&gt;PAT-Port Address Translation:&lt;/b&gt; This is like one to many. Your list of private ip addresses are translated to one public ip address. This uses source port no. of your local network to differentiate individual hosts or computers in your local network. This is also called &lt;b&gt;NAT Overload.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_CNtLfvlydfw/SxC4X0T8jrI/AAAAAAAADvw/WU2E_hNwlWk/s1600/topology.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_CNtLfvlydfw/SxC4X0T8jrI/AAAAAAAADvw/WU2E_hNwlWk/s400/topology.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;Lab:&lt;br /&gt;Local router:&lt;br /&gt;f0/0 - desktop&lt;br /&gt;f0/1 - vpcs1&lt;br /&gt;s1/0 - border router&lt;br /&gt;&lt;br /&gt;Border router:&lt;br /&gt;s1/0 - local router&lt;br /&gt;s1/1 - isp router&lt;br /&gt;&lt;br /&gt;Isp router:&lt;br /&gt;s1/1 - border router and f0/0 - vpcs2&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;Local router configuration:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_CNtLfvlydfw/SxDItIAIARI/AAAAAAAADxE/COIltJIBWVs/s1600/localconfig.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_CNtLfvlydfw/SxDItIAIARI/AAAAAAAADxE/COIltJIBWVs/s640/localconfig.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Border router configuration:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://3.bp.blogspot.com/_CNtLfvlydfw/SxGzXaGWUHI/AAAAAAAADyM/g0CIql3PwNM/s1600/bordercfg.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_CNtLfvlydfw/SxGzXaGWUHI/AAAAAAAADyM/g0CIql3PwNM/s640/bordercfg.jpg" /&gt;&lt;/a&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Isp router Configuration:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_CNtLfvlydfw/SxDOOnw8cEI/AAAAAAAADxk/swFA_YVCm9U/s1600/ispconfig.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_CNtLfvlydfw/SxDOOnw8cEI/AAAAAAAADxk/swFA_YVCm9U/s640/ispconfig.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Vpcs Configuration:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_CNtLfvlydfw/SxDJJn9ihKI/AAAAAAAADxc/RhgpVp4s7V4/s1600/vpcs.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_CNtLfvlydfw/SxDJJn9ihKI/AAAAAAAADxc/RhgpVp4s7V4/s640/vpcs.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Desktop( &lt;a href="http://crazy4tips.blogspot.com/2009/11/microsoft-loop-back-adapter-gns3.html"&gt;MS Loop back Adapter&lt;/a&gt;) gets 10.0.0.2 &amp;nbsp; 255.255.255.252, GW: 10.0.0.1, DNS:&amp;nbsp; 10.0.0.1&lt;/li&gt;&lt;li&gt;We will use EIGRP in Local and Border routers for routing protocol, so that desktop and vpcs can communicate with Border router via Local router. We will configure them both routers in Autonomous system no 10 so they become neighbours and exchange topology database.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="background-color: black; color: white;"&gt;local(config)#router&amp;nbsp; eigrp 10&lt;br /&gt;local(config-router)#network&amp;nbsp;&amp;nbsp; 10.0.0.0 &lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Border router should be able to communicate with both public and private networks. With Eigrp, border router is already communicating with our local networks. In real world, all local computers connect to border router and border router knows how to get to ISP router, these settings are given by ISP provider. For this lab, we will need to configure border router ourselves, it needs to know the routes. We can use any routing protocol but because we only have one network 99.0.1.0 to be included in the routing table, since 99.0.0.0 is directly connected, lets use static routing.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="background-color: black; color: white;"&gt;border(config)#router eigrp 10                                                  &lt;br /&gt;border(config-router)#network&amp;nbsp;&amp;nbsp;   10.0.0.0 &lt;br /&gt;border(config-router)#network &amp;nbsp; 99.0.0.0                                                         &lt;br /&gt;border(config)#ip&amp;nbsp;&amp;nbsp;  route&amp;nbsp;&amp;nbsp; 99.0.1.0 &amp;nbsp;&amp;nbsp; 255.255.255.252 &amp;nbsp;&amp;nbsp;&amp;nbsp;   99.0.0.2&lt;br /&gt;border(config)#ip&amp;nbsp;&amp;nbsp;&amp;nbsp; default-network &amp;nbsp;&amp;nbsp; 99.0.0.0&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;I also used 'ip default-network' command so EIGRP can adveterise it to local router.&lt;/li&gt;&lt;li&gt;With all the above setup we should be able to succefully ping within our local network and within our public i.e. 99.0.0.0 and 99.0.1.0 network. But we can not ping from local network to public network and thats where NAT comes into picture. NAT will translate our local ip addresses to public ip address so we can communicate with our public networks. We are going to implement NAT overload or PAT in our border router.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="background-color: black; color: white;"&gt;border(config)#ip&amp;nbsp;&amp;nbsp; nat&amp;nbsp;&amp;nbsp; pool&amp;nbsp;&amp;nbsp; test&amp;nbsp;&amp;nbsp; 99.0.0.1&amp;nbsp;&amp;nbsp; 99.0.0.1&amp;nbsp; netmast&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252&lt;br /&gt;border(config)# access-list&amp;nbsp;&amp;nbsp; 10&amp;nbsp;&amp;nbsp; permit&amp;nbsp;&amp;nbsp; 10.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.255.255&lt;br /&gt;border(config)# ip&amp;nbsp;&amp;nbsp; nat&amp;nbsp;&amp;nbsp; inside&amp;nbsp;&amp;nbsp; source&amp;nbsp;&amp;nbsp; list&amp;nbsp;&amp;nbsp; 10&amp;nbsp; pool&amp;nbsp;&amp;nbsp; test&amp;nbsp;&amp;nbsp; overload&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;First line creates a pool called 'test' with a range of public addresses. In this case only 99.0.0.1 because we're implementing NAT overload i.e. many-to-one. However, we can use more than one public IP.&lt;/li&gt;&lt;li&gt;Second line creates a list of our local addresses identified by no. '10' with 'permit' option.&lt;/li&gt;&lt;li&gt;Third line tells NAT to translate inside addresses that are specified in list no. 10 to addresses in pool named 'test', the 'overload' tells NAT to use port no.'s to identify a particular host in the local network.&lt;/li&gt;&lt;li&gt;Now we're left configuring interfaces as belonging to inside network or outside network in our border router. In this lab, s1/0 of border router belongs to inside network and s1/1 to the outside.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="background-color: black; color: white;"&gt;border(config)#int s1/0&lt;br /&gt;border(config-if)# ip nat inside&lt;br /&gt;border(config-if)#int s1/1&lt;br /&gt;border(config-if)#ip nat outside&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Verification:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="ltas-ad" id="mediaspace"&gt;&lt;object classid="clsid:D27CDB6E-11cf-96B8-444553540000" height="480" id="jwplayer1" name="jwplayer1" width="640"&gt;     &lt;param name="movie" value="http://www.timacheson.com/SkyDrive/DirectLinkRedirect?pageUrl=http://cid-08c287bccc782dea.skydrive.live.com/self.aspx/.Public/crazy4tips/jwplayer.swf"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="wmode" value="transparent"&gt;&lt;param name="flashvars" value="width=400&amp;height=320&amp;file=http://www.timacheson.com/SkyDrive/DirectLinkRedirect?pageUrl=http://cid-08c287bccc782dea.skydrive.live.com/self.aspx/.Public/crazy4tips/nat.flv&amp;plugins=ltas&amp;ltas.cc=wudofepwibbpvok"&gt;&lt;embed        id="jwplayer2"        name="jwplayer2"        src="http://www.timacheson.com/SkyDrive/DirectLinkRedirect?pageUrl=http://cid-08c287bccc782dea.skydrive.live.com/self.aspx/.Public/crazy4tips/jwplayer.swf"        width="640"        height="480"        allowscriptaccess="always"        allowfullscreen="true"        wmode="transparent"        flashvars="width=400&amp;height=320&amp;file=http://www.timacheson.com/SkyDrive/DirectLinkRedirect?pageUrl=http://cid-08c287bccc782dea.skydrive.live.com/self.aspx/.Public/crazy4tips/nat.flv&amp;plugins=ltas&amp;ltas.cc=wudofepwibbpvok" &gt;&lt;/embed&gt; &lt;/object&gt;&lt;br /&gt;&lt;/div&gt;&lt;script src="http://www.ltassrv.com/AdSrv/js/?cc=wudofepwibbpvok" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2481847082284475001-8008401401530579919?l=iknewnot.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://iknewnot.blogspot.com/feeds/8008401401530579919/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://iknewnot.blogspot.com/2009/12/network-address-translation.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2481847082284475001/posts/default/8008401401530579919'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2481847082284475001/posts/default/8008401401530579919'/><link rel='alternate' type='text/html' href='http://iknewnot.blogspot.com/2009/12/network-address-translation.html' title='Network Address translation'/><author><name>Freeman</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_CNtLfvlydfw/SxC4X0T8jrI/AAAAAAAADvw/WU2E_hNwlWk/s72-c/topology.jpg' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
