Showing posts with label networking. Show all posts
Showing posts with label networking. Show all posts

Wednesday, July 1, 2015

Hamlet question : can everything be "Natted" ?

Hi mates,
few days ago , with some friends of mine, we started a discussion about service or application that could be behind a firewall (so "Natted") and services that can't.
First of all what's a NAT ? You can find a tons of articles on internet about the Network Address Translation (RFC 1631).
Anyway the primary purpose of it is to avoid the unconscionable usage of public internet IPs.
So the NAT permit to map IPs between different address realms, in particular when one of these is not routable (ex. private IP addresses).
As the same private ranges (RFC 1918) can be used by several companies/users, they become, for their intrinsic nature, not routable in a public/common infrastructure where ranges are unique and duplicates are not admissible.
Here you have NAT !
The devices that come in play to make this communication possible usually sit at the firewall level, on the frontier.
In this way when an external customer/packet sender wants to communicate with a service that resides in a private area will comes in touch with a NAT device that make the communication possible making the "sender" unaware of the trick.