Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
>> This last week my wife and I were cleaning out the garage,
which we do on probably a quarterly basis when it gets all cluttered and you move it all out.
So we were moving some stuff, and I kind of, I had to wiggle the water heater a little bit
to move something behind it, and you know, continue on.
So later that morning we found this giant puddle just, you know, all over the floor
in the garage, and my wife was like, "What's this?"
And I looked up, and sure enough the water heater is dripping
because by wiggling I had broken one of the copper lines going to it,
like there was just a pinhole leaking, and it just kind of sprang out, and I was like, "Oh."
So we turn off the water, and my wife was like, "What have you got to do," and I was like,
"Well, I'm afraid I'm going to have to solder that."
Now let me tell you.
Since I've learned to solder, like this was a year ago a friend of mine was like, "Oh, yeah,
here's how you sweat the line, how you, you know, put the bead of solder in there,
and like any chance to solder something, I'm like, "I'm there" [laughter]
because it's awesome, and I came in and told my wife, I'm like,
"There's not much that makes you feel like a man than soldering some copper pipe,"
and she laughed at me, but nonetheless, I soldered the line, and that's what NAT is to me.
When I first learned how NAT, Network Address Translation, really works behind the scenes,
I was like, "That's awesome," and any chance I could get, you know, I...
we'd be at a friend's house and setting up a little link sys device for them or something
to route their Internet connection, I'm like, "You want to know how that works?"
And they'd, you know, always kind of look at me like...
and I'd say, "No, let me show you.
I want to show you how this works because it's amazing," and so NAT is one
of those cool concepts, and through all the years, it still has not lost its luster.
Now is its time short?
Maybe. Now it may fade away some day as IPV6 takes hold,
but I will say it is the staple of every network of the world.
I would challenge you to find me a network in this world that is connected
to the Internet that is not using NAT.
They're out there, but I mean I probably could count them on one hand.
So Network Address Translation is what we're all about.
We're going to talk about how it works.
Next nugget we'll tell you about how to set it up.
Did you know that you could build your own Internet?
All you have to do is go to your house and set up a network and then go to your neighbor
and say, "Hey, you want to join my network?"
And connect a cable to his house, and then tell him, "You've got to connect at least 5 neighbors
to you," and so they connect their 5 neighbors,
and you kind of start your own little pyramid Amway scheme or something like that, you know,
all your neighborhood connected, and before long it keeps exponentially growing,
and poof, worldwide span.
You've got your own Internet because that's really all the Internet is,
is just a big network.
Instead of houses, it started with some college universities that are like, "Hey,
let's share some files," and, you know, 4 universities connected together,
and other college campuses were like, "Hey, let's jump in on that,"
and then a business partnered in, and they jumped in, and then .com came along,
and someone was like, "We can sell stuff here?
Woo." And then, poof, you know, Internet explodes.
Everybody needs to be on there, and now it's one of the staples of every business is you have
to have an Internet connection really anymore to do business in most locations.
So the problem with that is we've now brought masses of devices and masses of equipment,
and there's a limited scope on the IPV4 address space.
There's not enough public IP address spaces or Internet valid IP addresses that are available.
So management entities were created, and the government got involved and said,
"Okay we will sell or provision blocks of IP addresses like, you know, we'll say the...
I'm just throwing one out there...
13.1.0.0/16, like that big block of IP addresses, 65,000 IP addresses,
we're going to give that to some service provider."
Let's just say AT&T.
I'm just throwing one out there, right?
So AT&T gets that, an then they provision it for their customers, and,
you know, somebody signs up for a DSL...
I don't even know if AT&T does DSL, but we'll go with it.
A DSL connection from AT&T, and AT&T says, "Okay, you can have one of our IP addresses
for a limited amount of time that you can use on your different devices."
So, I mean, they had to have ways of provisioning and allocating these IP addresses
because there are exponentially far more devices in the world today than there are IP addresses.
Now with this management in place, we also had to have something
that allowed people to create their own networks.
Like, you don't want to have to go to some management entity and go, you know,
to set up your house and say, "Hey, I'd to use, you know, 5 computers in my house.
Is that okay?"
I mean in the same way, take it this way.
You ever bought a cordless phone?
I mean, now, with cell phones, right?
Everybody's like, well, whatever, but I mean cordless phone for your house, right?
You don't have to go to the FCC and register for a broadcasting license for your cordless,
you know, 900 megahertz phone, or whatever kind of phone you have
because it is part of the unlicensed band.
I mean, you are technically broadcasting.
You're creating a signal that could interfere with others in the air, but the FCC,
meaning the government entity of the United States that governs, you know,
so nobody can just run their own radio station from home or something like that.
They have said that 900 megahertz, 2.4 gigahertz, and 5 gigahertz are unmanaged bands.
That's why you can set up your own little wireless network in your house.
You don't have to register for that.
So in this same way, with IP addresses, they said, "We need to let people set
up their own networks without actually going to the government and saying, 'Can I do this?
Am I allowed?'" So they came up with private addresses space I said that totally wrong...
private address space, and you've seen these before, right?
10.0.0.0 through 10.255.255.255.
Once somebody...
this is a weird one...
172.16.0.0 through 172.31.255.255, and that's a little chunk in the middle there.
This is Class A, this is Class B, and then Class C, those famous,
do-do-do-do, toot the trumpets, 192.168.
anything is considered private addresses.
So like private, wireless frequencies,
we can just use these addresses wherever we want because they're unmanaged.
You don't have to have a license to use them, but...
but, you know, let's say this is you and your company.
You've created your own little world on, let's just say, 192.168.1.0/24.
You know, you've got your own little server back here, your own little client.
You've got your own little network that's working great,
but the problem is 9 million people in the world are also using...
probably 9 billion.
Wait a second.
I'm exceeding the population, but you get the point.
Tons of people are using 192.168.1 in their home because it's unmanaged.
So we have to have a way of hiding your network from the world and yet still allowing you
to use this public world, and that's where NAT comes in.
Network Address Translation at its root translates from a...
well, let me just, you know, the technical definition, technically translates
from one IP address to another, but really the big picture is it translates
from private addresses, which work inside of your house and actually would work
on the Internet if service providers would let them through,
but it translates from private addresses to public addresses.
Now let me say one more quick thing before we move on here.
One of the biggest misnomers that I've heard, and you may have heard this, too,
I just want to debunk this right now.
A lot of people say, "Oh, yeah.
Those are non-routable IP addresses."
Have you ever that before, where somebody identifies those private addresses.
"Oh, those are non-routable IP addresses."
Totally not a good way to say it because they work perfectly fine.
I mean, you can set up...
Oh, I'm flabbergasted...
I'm appalled at that because this entire series we've been setting up routing.
I mean we went in OSPF and set up, you know, these routers on 192.168.1 and .2 and .3,
and we said, "Okay, this can reach this," and we're routing those just fine.
So if you're going to say they're non routable, I would say they're non routable
but add in there, always add in, on the Internet.
They're non routable on the Internet.
Now even that, I'm like ew-w-w, because if they were to somehow get
into the Internet, they would route just fine.
What really happens is to be a service provider, to be an ISP, you are supposed to block,
these are all considered RFC1918, and if you ever want to know what is the standard
that specifies private addresses?
RFC1918. It's the only way I can tell you off the top of my head, but as an ISP,
you are supposed to block, you know, you've got your customer, we'll say,
over here that is coming in, you are supposed to block all these addresses from coming in.
There have been mistakes.
ISP's have forgotten to block customer IP addresses, and the customer has forgotten
to turn on NAT and to what the public addresses, and there have been cases, you can look them up,
to where private IP addresses have gotten into the Internet, and it was actually so bad,
it was over in Europe somewhere, that I can't quite remember the whole...
This was a long time ago, but essentially there was one ISP that forgot to block their customer,
and all these other ISP's trusted this ISP.
So they didn't put the block here because they were like, "Well, why do block private."
They were assuming that, you know, our ISP friend down there is blocking it.
So we don't need to put those blocks here, and they actually had a case
where like a whole chunk of Europe went down on the Internet
because of these private addresses had leaked in there.
Well, no more.
I'm sure that's taught everybody a big lesson.
So the point is that private addresses route great.
They just are blocked from getting in from the Internet.
When you think about NAT, you can think of it as an umbrella of three different flavors.
You can have static NAT-very common.
You can have dynamic NAT, which is not very common, and then you can have something
that some people call it NAT overload.
Some people call it PAT.
That's probably the more common word , Port Address Translation, which is insanely common,
like that's the staple that just about every business has.
What PAT does...
I'm going to talk about all 3, but I want to talk about the most popular one first
because almost every business in the world uses it.
What this one does is stretch an IP address further than I'm sure the founding fathers
of the Internet ever thought it could go.
So here's...
let me give you the big picture concept of PAT.
So what...
every time you have a connection, and this, you know, to understand NAT you have
to understand how devices communicate, right?
So let's think back, I mean, go back to your old nugget number 5 or 6 of the series
where we were starting to talk about, okay, communication, we've got a source IP address,
let's just say 10.1.1.10, and we've got a destination IP address 10.1.1.100,
no routers in the middle to garble this all up, and let's just say this is a web server,
this is a client, and I open my web browser and try and access that, what happens?
Well that's where we said, okay, the Windows, you know, Windows or Lenox or OX,
whatever you're using here generates a source port number dynamically.
It says, "Okay, I'm coming form the source 1000...
well, let's just do 1892.
It makes those up, and I'm going to a destination, now if this is a web server,
I'm going to a destination of port 80, right, and we...
I'm doing a little review here of early topics.
We call that it creating a socket because this says, "Okay,
I'm coming from the source 10.1.1.10:1892, and I'm going to the destination of 10.1.1.100:80."
And when this guy communicates back he comes from the source of 80 and goes to a destination
of 1892, and that's how Windows knows, oh, you're going to this, you know,
Google Chrome window or whatever browser we happen to use to browse at.
So that's how it works.
Now you can...
let's think a little bit further.
How many port numbers are there?
I mean, we picked 1892, but really, how many are there?
Well for TCP and UDP there's 65,535 usable ports that you're able
to work with, you know, outside of...
I mean you can get into well known ports and blah, blah, blah, but I mean 65,000 ports.
Now is this...
question...
is this computer ever going to tap that out?
No. No. I'm like well...
I always try and find the exceptions, right?
No, it's not because you just can't open enough applications.
That computer would crash long before it would max those things out.
So the point is we have all these port numbers that we can use.
Okay. Okay, we've established a foundation.
Now here's how PAT works.
We have a network.
It could be, you know, 2 clients like we have here.
It could be 100 clients.
It could be 1,000 clients, whatever we have running inside of our organization,
and we've got a router in place, let's say 192.168.1.1 is the default gateway
of these guys, and we've got the public IP address assigned, 200.1.1.1, and this, you know,
this would actually go to a router of the ISP...
whatever ISP you are, and this default route would point out this way.
So when this guy...
let's go to this guy, and he opens a web browser, you know, Google Chrome and goes
to a server out on the Internet-we'll just say it is CBTNUGGETS.com, and...
if I can write.
There we go.
So he goes to CBTNUGGETS.com.
He's going to automatically, just like we saw over there, generate its own source port number.
So he's going to say, "Okay, Chrome, I'm going to generate source port...
I'll use my diagram...
6711." That's my source.
That's where I'm going to, and I'm going to go to a destination of, let's just say,
CBTNUGGETS.com because it's easy to write.
It's 1.1.1.1.
I'm going to go to a destination of 80, right there, right?
So that request will come into the router that is configured to do PAT
or NAT overload is what CISCO config calls it.
So it receives that request and it goes, "Okay, I'm going to translate you
because I know these private addresses do not work on the Internet.
If I were to send you out as 192.168.50, the ISP would say [noise]
and block you, and you would die right there.
So I'm going to translate you to 200.1.1.1.
Now the way I'm going to do that is I'm going to use your source port number to make you unique."
You see what happens.
So it creates a little table inside, and the table's actually bigger than this, but it says,
okay the inside address, 192.168.1.50, it's like a spreadsheet inside the router,
it's actually going to go to the outside address 200.1.1.1,
and it's going to use that same source port number.
So that way now it comes out as 200.1.1.1 goes to CBTNUGGETS.com.
CBTNUGGETS sees it coming from the source of 200.1.1.1:6711 and,
you know, sends the webpage back to that.
It's received here on the router, goes, oh, okay, well,
you're actually going back into this guy.
So that's what allows this guy at the same time to open up a different web browser, well,
Chrome, or I'm not talking about like Firefox or anything like that,
but let's just say he opens Firefox or Chrome or whatever and goes to the same web.
I mean, he could go to CBTNUGGETS.com.
Well, his computer, it randomly grabs a port from 65,535, and it's going to say, "Okay,
well I picked port 15396, and I want to go to CBTNUGETS.com."
So he goes out to CBTNUGGETS.com.
Are you following me here?
And I want to make sure you catch me.
So he generated his own source port.
Windows did that for him behind the scenes.
NAT kicked in and said, "Okay, I'm going to use that source port number so as you go
through that router, I'm going to translate you to my public address,
but I'm going to put a little colon 1536," and do you kind
of get why it's called PAT, Port Address Translation?
It's using the ports to make all these requests look unique,
and I'm going to send you to CBTNUGGETS.com.
If CBTNUGGETS.com gets a request from 200.1.1.1:6711
and gets a second request at the same exact time...
let's just say they did this at the same time because they both wanted their CBTNUGGETS,
and it sees a request to 1536, it actually sees these as two unique requests.
It doesn't see them as one IP address.
It's like, "Whoa, this must be the same thing."
No it looks at the port number, and it's like, "Oh, I've got two unique requests."
So, okay, in theory, in theory...
we're talking theory, we could use this one IP address
to service 65,535 computers sitting behind there.
You could share that to 65,535 devices in theory.
Now here, let me now get to...
I know a lot of you are analytical, and you're like, okay, okay, what if....
Let me see if I can predict a question rolling around in somebody's mind.
I'm feeling you right now.
You're going what if, 1 in 65,000 chance, this computer opens a web browser and goes
to CBTNUGGETS and at the same time this computer opens a web browser and goes to CBTNUGGETS.com,
and they just happened to pick the same port number.
Did I read your mind?
So both of them picked 65...
6711. Not a big deal.
Yeah, well how's it not a big deal?
What the router does is just say, you know, let's say this guy got there...
one of them's going to have to get there first.
The packet, the router can't two packets at the same time.
It has to have one in front of the other.
So whoever gets there first gets the 6711.
When this guy comes in, he's like, "Oh, I want 6711, too."
The router's like, "Oh, like I don't have that.
That's all right, I'm going to give you 6712."
That's the next free one that I have in my list or whatever, the next open port.
So these don't have to match.
I mean you figure the router's got the big Excel spreadsheet thing going, right?
It going to have to like, "Oh, well, oh no.
I'm sorry.
I don't have that available."
It's totally fine.
So it will increment that and life is good, and, you know, this guy, you know,
so it's seen from CBTNUGGETS as 6712, but when it replies back,
it's like, "Oh, well, 6712 is really 6711.
So let me send that back to him."
So that's how it works it all out.
No biggie there.
And, I know I was kind of like stretching it, making it sound like, oh, you know 1 in 65,000?
Truth is, this happens all the time, all the time because...
and this is where I go back to the theory-65,000 devices.
It's a theory because when you open a device, let me show you.
Let me show you this.
I'm going to open a command prompt, and I'm just going to open a web browser to...
how is it...
technet right there, right?
So let's go to the biggest waste of time website on the Internet, and msn.com.
"Dozens injured after ferry hits NY city dock."
So, you know, when I go here, this isn't just one website.
I think I told you this early on in the series, right?
I've got a webserver that gives you this picture.
I've got these fancy looking ladies.
I've got Geico.
I mean, all of this webpage is just an assembly of, wow, this is creepy, but an assembly of...
You ever see that movie with Will Smith, the...
oh, where they...
the creatures like [noise].
That's what the guy looks like.
So it's an assembly of all kinds of different webpages.
So when I go to the command prompt and type in netstat, I actually see all kinds...
now look at this.
Firefox with bing.
That's funny.
So there's all kinds of different servers that I was actually sent to for this one.
Now look at this.
These are all like my one computer used this and this and this and this and this and this.
I mean these are all source port numbers, and it's kind of hanging up.
The reason it's taking a long time is because it's trying to figure out what...
well, actually because I clicked on there and it paused.
It's trying to figure out what name each one of these IP addresses actually resolve to.
So my one computer actually ended up using...
I mean, the list continues to build, right?
Probably, I don't know, 50 different port numbers just to go to msn.com
and see the scary guy in the scene.
So the truth is, I mean, you...
in theory if every computer only went to one place and it only used one port number, yes,
we could get the 65,000, but nowadays, I mean, you're probably with people web surfing,
you could probably stretch this to maybe 300, maybe, you know, 500.
It depends on your web surfing people, how many people are wasting life on msn.com
versus doing work and all at the same time, and, I mean,
these things time out after a certain amount of time.
So your mileage may vary but you can add multiple IP addresses to this pool
that when one maxes out on port numbers, the next one jumps in there and takes over,
but I digress into a lot of the specifics.
I just want to answer a lot of the questions I know rattle
around people's mind when I bring this up.
At its root, if I could clear this up, this is how PAT works.
This is how you can use one IP address for many internal ones is
by sharing it using the magic of port numbers.
Now I have a different slide for static NAT, but let me talk about dynamic really quick
because it's similar to PAT but not really.
So dynamic, what it allows you to do is specify a pool of addresses that we could...
we'll just say they are public and a pool of private addresses.
You know, we'll call it pool-private, and what you can do
with that is have one-to-one translations going through it.
So let's just say I say my private pool is 192.168.1.0 through 250,
and I say my public pool is actually 200.1.1.,
well let's just say 1 to 250 because you can't use 0.
So 1 to 250 over here.
So what will happen is, you know, the very first one
to go through, will get the first address here.
The second one to go through will get the second address.
It's just a series of one-to-one links made between the public and private IP addresses.
Now you don't really get any savings.
It's not like you save IP addresses when you do this,
which is the reason why it's not used too often.
The main place dynamic NAT is used, and it's not something we get into here,
is where you have overlapping addresses.
So let me give you a scenario.
Let's say you've got organization A over here that uses, let's just say 10.1.0.0/16,
and you've got organization B over here that uses the same address range, right?
And organization A does a hostile takeover and buys organization B.
So I don't know why I add hostile into there.
It's just part of my nature.
So what you can do is you can introduce a router in between that uses dynamic NAT
to where organization A looks like, we'll just say, 10.2.0.0/16 to organization B,
and organization B may be looks like 10.3.0.0 to organization A. So that way,
you can kind of merge the two and they don't really know they have overlapping addresses
because NAT is hiding it with this pool.
You create a pool of addresses in 10.2 then line it up to organization A and create a pool
in 10.3 and line it up to organization B. So that's
where you see Dynamic NAT used, and it's only used temporarily.
Obviously that situation doesn't want to hang around for any amount of time.
So the last form of NAT that I want to talk about is Static NAT,
and this one is used all the time.
So we've got, you know, PAT, which is just everywhere, and then we have Static NAT,
which is used all over the place.
A static NAT is a one-to-one mapping from the inside to outside that doesn't change.
As you saw before with PAT, you know, these little port number deals
that we're running where, you know, this guy opens up a web browser and accesses cisco.com,
you know, he uses his port number.
Well as soon as he closes his web browser, that session dies, and that NAT port ends up back
into the pool where it can be used by anybody again, right?
But there's times where you want to create a one-to-one mapping.
Maybe I say this one is always mapped to the IP address 200.1.1.2, which is, you know,
the ISP believes you have that addresses because they've given it to you.
So when somebody, you know, this is usually let's say this one is actually an email server,
right?
So when you're running an email server in an organization, emails are coming in from all
over the world, and they need to be able to reach your router.
Now how would they know to come here?
How would all emails know to come right here?
Well, you would go to a DNS server.
Let's say, let's say your organization NUGGETLAB.com Well what you do is wherever you
registered that domain, you would go to the DNS control panel
and create a mx record, which is the mail exchange.
You would say, okay, any time somebody sends me mail, send it to, you know, 200.1.1.2,
and so that, you know, the mail servers look up that mx record.
They would end up here, and you create a static NAT mapping that says 200.1.1.2 really maps
to my email server at 192.168.1.51.
So this is usually used for inbound, you know it's where things coming in,
but now this time this one goes out, he will also go out as 200.1.1.2.
He doesn't go into the general pool over here.
Now you can use static NAT as a one-to-one IP address,
or you can even break it down even further.
You could say 200.1.1.2 on port 25 maps to this email server on port 25.
So, by the way, port 25 is SMTP.
That's what email servers use when they receive email.
So that allows you to say just that port maps to that email server.
Why is that good?
Because public IP addresses are at a premium, you know.
You want to conserve them as much as possible.
So you might be able to, you know, use that for other things.
You might say, well, 200.1.1.2:80, you know, HTTP services, those will actually go
to a third server inside of here.
Maybe we've got a server 192.168.1.100, and that's our web server that we're running.
So if somebody accesses web services it actually goes to that 192.168.1.100 on port 80,
and I can now kind of split this IP address into all these different services.
So you say, oh, well, actually I also want to sent 200.1.1.2:443,
which is HTTPS, to that same destination.
So you can really split this up, you know, give it the whole IP address per server,
or you can break it down and say, well, these go to these ports go to these different servers,
and really get the most out of each IP address.
Those are the concepts, and if it's at all fuzzy right now, and hopefully it's not, but if it is,
it'll get much clearer when we start doing the configuration in the next nugget.
So let's review.
We have seen what network address translation is.
We have seen there's many ways to go public to private, and we saw the static way,
the dynamic way, and then using PAT as a way to do it.
Almost everybody in the world using PAT, almost every business in the world using static NAT
to make servers available from the inside out, and then we saw some,
I'll say some, of the NAT terms and locations.
We saw the inside, the outside addresses, but when we get to the configuration,
you might remember I said there's actually more to this where we get to things known
as inside local addresses and inside global addresses.
You'll start being able to identify where these different IP addresses are in the grand scheme
of things, but that's in the configuration.
So for now, I hope this has been informative for you, and I'd like to thank you for viewing.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.