Network Address Translation (NAT)
Network Address Translation (NAT)
TRANSLATION (NAT)
Understanding How Private Networks Connect to the Internet
BY
PATTABHISAIRAM KHANDAVILLI
What is NAT?
It conserves IPv4 addresses and adds a security layer by masking internal IPs. NAT replaces source IP
addresses to communicate externally while preserving private network structure.
Why is NAT Important?
THE ROUTER INTERCEPTS THE PACKET AND REPLACES THE SOURCE IP ADDRESS (PRIVATE IP) WITH ITS OWN PUBLIC IP
ADDRESS.
THE ROUTER RECORDS THIS CHANGE IN A NAT TRANSLATION TABLE, NOTING THE PRIVATE IP AND PORT NUMBER
WHEN THE SERVER REPLIES, THE ROUTER CHECKS THE NAT TABLE AND REPLACES THE PUBLIC IP BACK WITH
THE CORRECT PRIVATE IP AND PORT
ROUTER: CHANGES SOURCE IP TO ITS PUBLIC IP 203.31.220.134AND ASSIGNS A UNIQUE PORT (E.G.,
45678).
INTERNET: WEB SERVER SEES REQUEST FROM 203.0.113.5:45678 AND SENDS A RESPONSE.
ROUTER: MATCHES INCOMING RESPONSE TO THE NAT TABLE, TRANSLATES BACK TO 192.168.1.10, AN
FORWARDS THE PACKET
WHEN REPLIES COME, THE RECEPTIONIST DELIVERS THEM TO THE CORRECT EMPLOYEE.
Types of NAT: Static NAT
One-to-One Mapping
Maps each private IP to a unique public IP address.
USE CASES
IDEAL FOR HOSTING SERVERS REQUIRING CONSISTENT PUBLIC ADDRESSES
CONFIGURATION
TYPES OF NAT: DYNAMIC NAT
MANY-TO-FEW MAPPING
MAPS MULTIPLE PRIVATE IPS TO A POOL OF PUBLIC IPS
DYNAMICALLY.
USE CASES
PROVIDES CONTROLLED INTERNET ACCESS FOR INTERNAL USERS.
CONFIGURATION
ACCESS-LIST DEFINES INTERNAL IPS; POOL DEFINES PUBLIC IPS.
PORT ADDRESS TRANSLATION (PAT) / NAT OVERLOAD
MANY-TO-ONE MAPPING
MULTIPLE PRIVATE IPS SHARE ONE PUBLIC IP USING
UNIQUE PORTS.
COMMON USAGE
WIDELY USED IN HOME ROUTERS AND SMALL OFFICES.
CONFIGURATION
EXAMPLE: IP NAT INSIDE SOURCE LIST 1 INTERFACE GIGABITETHERNET0/1 OVERLOAD
NAT TRAVERSAL ISSUES
CHALLENGE
NAT BLOCKS EXTERNAL HOSTS FROM IINITATIING CONNECTIONS
PORT FORWARDING
TRAVERSAL TECHNIQUES
UPNP
DEVICES CAN AUTO-CONFIGURE PORT FORWARDING, BUT WITH RISKS.
NAT AND SECURITY CONSIDERATIONS
SECURITY ROLE
NAT HIDES INTERNAL STRUCTURE FROM EXTERNAL THREATS.
LIMITATIONS
NOT A SUBSTITUTE FOR A FULL FIREWALL SOLUTION.
VULNERABILITIES
UPNP AND POOR PORT FORWARDING CAN EXPOSE RISKS.
BEST PRACTICE
USE NAT ALONGSIDE FIREWALLS AND AUDIT RULES REGULARLY.
ADVANTAGES OF NAT
DISADVANTAGES OF NAT
VARIIETY OF TYPES
STATIC,DYNAMIC , PAT SERVERS DISTINCT NETWORK NEEDS
IPV6
IPV6 WILL EVENTUALLY REMOVE THE NEED FOR NAT
THANK YOU
TEAM