CCIE Service Provider Exam Certification Guide - NAT Network Address Translation
1 Introduction to NAT
Advantages and Disadvantages of NAT: Advantages: Save IP addresses, handle address duplication, increase flexibility, eliminate address renumbering, and hide internal IP addresses. Disadvantages: increased latency, lost end-to-end IP tracking process, can not support some specific applications (such as MSN5.0 and below) need more memory to store a NAT table, need more CPU The process of processing NAT. The concept of NAT: INSTDE (internal look) and OUTSIDE (external look). Local and global.
Principle of NAT Convert the internal source address, convert the external source address, PAT, and solve the problem of address overlap. Address classification IL 2. IG 3. OG 4. OL internal local, the address is not announced externally, the external can know the internal device externally, the address distributed to the external device, will not be advertised to the external external, through this address, the internal device can know the external device.
NAT uses NAT address translation table for address mapping in cisco router NATrouter#show ip nat translations Pro Inside global 203.10.5.23 203.10.5.23 --inside local 192.168.2.23 192.168.2.23 --Outside local 172.16.80.91 --172.16.80.91 Outside global 192.31.7.130 --192.31.7.130
The NATrouter# address translation table starts a timer when an entry is added. If it times out, the entry is removed. The default time is 86400s (24h). It can be modified by ip nat translation timeout.
2 NAT and ISP migration
When the ISP changes, the ISP can be migrated through NAT with minimal changes to the internal network.
3 NAT in multiple AS systems
Before there is no NAT, you need to make holes in the BGP routing entries advertised by the ISP.
After using NAT, you can use NAT to address the address segment of one ISP to another ISP.
Or use RFC1918 to reserve the address, then do NAT on both ISP's border routers.
However, this method is limited to small-scale networks. Many routers do not support NAT wire-speed packets, so when there are more hosts, a large delay will occur.
4 PAT
Cisco maps multiple ips to an ip and maps them to different ports via PAT
5 NAT Implementing a Virtual Server
NAT and Virtual Server
6 NAT Implements Load Balancing
NAT and TCP Load Distribution
7 Some shortcomings of NAT
Due to the comprehensive processing of IP and TCP headers by NAT, some services will be abnormal in use.
1. The header checksum needs to be recalculated
2. Encryption services such as IPSec will not work because NAT cannot modify the Ip header.
3. ICMP packet was modified.
4. Static NAT is required for DNS resolution
5. FTP requires the server to open passive mode and transfer files using PASV
CCIE SP exam is much more than other cisco exam. So I will strongly recommend can review ccie sp written 400-021 dumps and ccie sp lab workbooks to pass exam more easily. good luck for you ccie sp journey.
https://evedumps.com/sp-400-021-dumps
https://evedumps.com/sp-lab-workbooks
评论
发表评论