Kamis, 19 Februari 2009

WLAN

A wireless LAN (shortly WLAN) is a wireless local area network that links two or more computers or devices using spread-spectrum or OFDM modulation technology based to enable communication between devices in a limited area. This gives users the mobility to move around within a broad coverage area and still be connected to the network.

For the home user, wireless has become popular due to ease of installation, and location freedom with the gaining popularity of laptops. Public businesses such as coffee shops or malls have begun to offer wireless access to their customers; some are even provided as a free service. Large wireless network projects are being put up in many major cities. Google is even providing a free service to Mountain View, California[1] and has entered a bid to do the same for San Francisco.[2] New York City has also begun a pilot program to cover all five boroughs of the city with wireless Internet access.[citation needed]
$$$ Contents $$$$


* 1 History
* 2 Benefits
* 3 Disadvantages
* 4 Architecture
o 4.1 Stations
o 4.2 Basic service set
o 4.3 Extended service set
o 4.4 Distribution system
* 5 Types of wireless LANs
o 5.1 Peer-to-peer
o 5.2 Bridge
o 5.3 Wireless distribution system
* 6 Roaming
* 7 See also
* 8 References


[edit] History
An embedded RouterBoard 112 with U.FL-RSMA pigtail and R52 mini PCI Wi-Fi card widely used by wireless Internet service providers (WISPs) in the Czech Republic.

In 1970 University of Hawaii, under the leadership of Norman Abramson, developed the world’s first computer communication network using low-cost ham-like radios, named ALOHAnet. The bi-directional star topology of the system included seven computers deployed over four islands to communicate with the central computer on the Oahu Island without using phone lines.[3]

"In 1979, F.R. Gfeller and U. Bapst published a paper in the IEEE Proceedings reporting an experimental wireless local area network using diffused infrared communications. Shortly thereafter, in 1980, P. Ferrert reported on an experimental application of a single code spread spectrum radio for wireless terminal communications in the IEEE National Telecommunications Conference. In 1984, a comparison between Infrared and CDMA spread spectrum communications for wireless office information networks was published by Kaveh Pahlavan in IEEE Computer Networking Symposium which appeared later in the IEEE Communication Society Magazine. In May 1985, the efforts of Marcus led the FCC to announce experimental ISM bands for commercial application of spread spectrum technology. Later on, M. Kavehrad reported on an experimental wireless PBX system using code division multiple access. These efforts prompted significant industrial activities in the development of a new generation of wireless local area networks and it updated several old discussions in the portable and mobile radio industry.

The first generation of wireless data modems was developed in the early 1980s by amateur radio operators, who commonly referred to this as packet radio. They added a voice band data communication modem, with data rates below 9600-bit/s, to an existing short distance radio system, typically in the two meter amateur band. The second generation of wireless modems was developed immediately after the FCC announcement in the experimental bands for non-military use of the spread spectrum technology. These modems provided data rates on the order of hundreds of kbit/s. The third generation of wireless modem then aimed at compatibility with the existing LANs with data rates on the order of Mbit/s. Several companies developed the third generation products with data rates above 1 Mbit/s and a couple of products had already been announced by the time of the first IEEE Workshop on Wireless LANs."[4]
54 MBit/s WLAN PCI Card (802.11g)

"The first of the IEEE Workshops on Wireless LAN was held in 1991. At that time early wireless LAN products had just appeared in the market and the IEEE 802.11 committee had just started its activities to develop a standard for wireless LANs. The focus of that first workshop was evaluation of the alternative technologies. By 1996, the technology was relatively mature, a variety of applications had been identified and addressed and technologies that enable these applications were well understood. Chip sets aimed at wireless LAN implementations and applications, a key enabling technology for rapid market growth, were emerging in the market. Wireless LANs were being used in hospitals, stock exchanges, and other in building and campus settings for nomadic access, point-to-point LAN bridges, ad-hoc networking, and even larger applications through internetworking. The IEEE 802.11 standard and variants and alternatives, such as the wireless LAN interoperability forum and the European HiperLAN specification had made rapid progress, and the unlicensed PCS Unlicensed Personal Communications Services and the proposed SUPERNet, later on renamed as U-NII, bands also presented new opportunities."[5]

Originally WLAN hardware was so expensive that it was only used as an alternative to cabled LAN in places where cabling was difficult or impossible. Early development included industry-specific solutions and proprietary protocols, but at the end of the 1990s these were replaced by standards, primarily the various versions of IEEE 802.11 (Wi-Fi). An alternative ATM-like 5 GHz standardized technology, HiperLAN/2, has so far not succeeded in the market, and with the release of the faster 54 Mbit/s 802.11a (5 GHz) and 802.11g (2.4 GHz) standards, almost certainly never will.

In November 2007, the Australian Commonwealth Scientific and Industrial Research Organisation (CSIRO) won a legal battle in the US federal court of Texas against Buffalo Technology which found the US manufacturer had failed to pay royalties on a US WLAN patent CSIRO had filed in 1996. CSIRO are currently engaged in legal cases with computer companies including Microsoft, Intel, Dell, Hewlett-Packard and Netgear which argue that the patent is invalid and should negate any royalties paid to CSIRO for WLAN-based products.[6]

$$$$$$$$$$$$$$$$ Benefits $$$$$$$$$$$$$$$$$

The popularity of wireless LANs is a testament primarily to their convenience, cost efficiency, and ease of integration with other networks and network components. The majority of computers sold to consumers today come pre-equipped with all necessary wireless LAN technology. Benefits of wireless LANs include:

Convenience
The wireless nature of such networks allows users to access network resources from nearly any convenient location within their primary networking environment (home or office). With the increasing saturation of laptop-style computers, this is particularly relevant.

Mobility
With the emergence of public wireless networks, users can access the internet even outside their normal work environment. Most chain coffee shops, for example, offer their customers a wireless connection to the internet at little or no cost.

Productivity
Users connected to a wireless network can maintain a nearly constant affiliation with their desired network as they move from place to place. For a business, this implies that an employee can potentially be more productive as his or her work can be accomplished from any convenient location. For example, a hospital or warehouse may implement Voice over WLAN applications that enable mobility and cost savings.[7]

Deployment
Initial setup of an infrastructure-based wireless network requires little more than a single access point. Wired networks, on the other hand, have the additional cost and complexity of actual physical cables being run to numerous locations (which can even be impossible for hard-to-reach locations within a building).

Expandability
Wireless networks can serve a suddenly-increased number of clients with the existing equipment. In a wired network, additional clients would require additional wiring.

Cost
Wireless networking hardware is at worst a modest increase from wired counterparts. This potentially increased cost is almost always more than outweighed by the savings in cost and labor associated to running physical cables.
$$$$$$$$$$$$$ Disadvantages $$$$$$$$$$$$$$

Wireless LAN technology, while replete with the conveniences and advantages described above, has its share of downfalls. For a given networking situation, wireless LANs may not be desirable for a number of reasons. Most of these have to do with the inherent limitations of the technology.

Security
Wireless LAN transceivers are designed to serve computers throughout a structure with uninterrupted service using radio frequencies. Because of space and cost, the antennas typically present on wireless networking cards in the end computers are generally relatively poor. In order to properly receive signals using such limited antennas throughout even a modest area, the wireless LAN transceiver utilizes a fairly considerable amount of power. What this means is that not only can the wireless packets be intercepted by a nearby adversary's poorly-equipped computer, but more importantly, a user willing to spend a small amount of money on a good quality antenna can pick up packets at a remarkable distance; perhaps hundreds of times the radius as the typical user. In fact, there are even computer users dedicated to locating and sometimes even cracking into wireless networks, known as wardrivers. On a wired network, any adversary would first have to overcome the physical limitation of tapping into the actual wires, but this is not an issue with wireless packets. To combat this consideration, wireless networks users usually choose to utilize various encryption technologies available such as Wi-Fi Protected Access (WPA). Some of the older encryption methods, such as WEP are known to have weaknesses that a dedicated adversary can compromise. (See main article: Wireless security.)

Range
The typical range of a common 802.11g network with standard equipment is on the order of tens of metres. While sufficient for a typical home, it will be insufficient in a larger structure. To obtain additional range, repeaters or additional access points will have to be purchased. Costs for these items can add up quickly. Other technologies are in the development phase, however, which feature increased range, hoping to render this disadvantage irrelevant. (See WiMAX)

Reliability
Like any radio frequency transmission, wireless networking signals are subject to a wide variety of interference, as well as complex propagation effects (such as multipath, or especially in this case Rician fading) that are beyond the control of the network administrator. One of the most insidious problems that can affect the stability and reliability of a wireless LAN is the microwave oven.[8] In the case of typical networks, modulation is achieved by complicated forms of phase-shift keying (PSK) or quadrature amplitude modulation (QAM), making interference and propagation effects all the more disturbing. As a result, important network resources such as servers are rarely connected wirelessly.

Speed
The speed on most wireless networks (typically 1-108 Mbit/s) is reasonably slow compared to the slowest common wired networks (100 Mbit/s up to several Gbit/s). There are also performance issues caused by TCP and its built-in congestion avoidance. For most users, however, this observation is irrelevant since the speed bottleneck is not in the wireless routing but rather in the outside network connectivity itself. For example, the maximum ADSL throughput (usually 8 Mbit/s or less) offered by telecommunications companies to general-purpose customers is already far slower than the slowest wireless network to which it is typically connected. That is to say, in most environments, a wireless network running at its slowest speed is still faster than the internet connection serving it in the first place. However, in specialized environments, higher throughput through a wired network might be necessary. Newer standards such as 802.11n are addressing this limitation and will support peak throughput in the range of 100-200 Mbit/s.

Wireless LANs present a host of issues for network managers. Unauthorized access points, broadcasted Service set identifiers (SSIDs), unknown stations, and spoofed MAC addresses are just a few of the problems addressed in WLAN troubleshooting. Most network analysis vendors, such as Network Instruments, Network General, and Fluke, offer WLAN troubleshooting tools or functionalities as part of their product line.
$$$$$$$$$$ Architecture $$$$$$$$$$$$$$$$$

@@@@@@@ Stations @@@@@@@@@@

All components that can connect into a wireless medium in a network are referred to as stations.

All stations are equipped with wireless network interface cards (WNICs).

Wireless stations fall into one of two categories: access points, and clients.

Access points (APs), normally routers, are base stations for the wireless network. They transmit and receive radio frequencies for wireless enabled devices to communicate with.

Wireless clients can be mobile devices such as laptops, personal digital assistants, IP phones, or fixed devices such as desktops and workstations that are equipped with a wireless network interface.
@@@@@@@@ Basic service set @@@@@@@@@

The basic service set (BSS) is a set of all stations that can communicate with each other.

There are two types of BSS: Independent BSS (also referred to as IBSS), and infrastructure BSS.

Every BSS has an identification (ID) called the BSSID, which is the MAC address of the access point servicing the BSS.

An independent BSS (IBSS) is an ad-hoc network that contains no access points, which means they can not connect to any other basic service set.

An infrastructure can communicate with other stations not in the same basic service set by communicating through access points.

@@@@@@@ Extended service set @@@@@@@@@@@@

An extended service set (ESS) is a set of connected BSSes. Access points in an ESS are connected by a distribution system. Each ESS has an ID called the SSID which is a 32-byte (maximum) character string. For example, "linksys" is the default SSID for Linksys routers.

@@@@@@ Distribution system @@@@@@

A distribution system (DS) connects access points in an extended service set. The concept of a DS can be used to increase network coverage through roaming between cells.

@@@@@@@@ Types of wireless LAN @@@@@@@@

@@@@@@ Peer-to-peer @@@@@@@@
Peer-to-Peer or ad-hoc wireless LAN

An ad-hoc network is a network where stations communicate only peer to peer (P2P). There is no base and no one gives permission to talk. This is accomplished using the Independent Basic Service Set (IBSS).

A peer-to-peer (P2P) network allows wireless devices to directly communicate with each other. Wireless devices within range of each other can discover and communicate directly without involving central access points. This method is typically used by two computers so that they can connect to each other to form a network.

If a signal strength meter is used in this situation, it may not read the strength accurately and can be misleading, because it registers the strength of the strongest signal, which may be the closest computer.

802.11 specs define the physical layer (PHY) and MAC (Media Access Control) layers. However, unlike most other IEEE specs, 802.11 includes three alternative PHY standards: diffuse infrared operating at 1 Mbit/s in; frequency-hopping spread spectrum operating at 1 Mbit/s or 2 Mbit/s; and direct-sequence spread spectrum operating at 1 Mbit/s or 2 Mbit/s. A single 802.11 MAC standard is based on CSMA/CA (Carrier Sense Multiple Access with Collision Avoidance). The 802.11 specification includes provisions designed to minimize collisions. Because two mobile units may both be in range of a common access point, but not in range of each other. The 802.11 has two basic modes of operation: Ad hoc mode enables peer-to-peer transmission between mobile units. Infrastructure mode in which mobile units communicate through an access point that serves as a bridge to a wired network infrastructure is the more common wireless LAN application the one being covered. Since wireless communication uses a more open medium for communication in comparison to wired LANs, the 802.11 designers also included shared-key encryption mechanisms: Wired Equivalent Privacy (WEP), Wi-Fi Protected Access (WPA, WPA2), to secure wireless computer networks.

@@@@@@ Bridge@@@@@@

A bridge can be used to connect networks, typically of different types. A wireless Ethernet bridge allows the connection of devices on a wired Ethernet network to a wireless network. The bridge acts as the connection point to the Wireless LAN.

[edit] Wireless distribution system

Main article: Wireless Distribution System

When it is difficult to connect all of the access points in a network by wires, it is also possible to put up access points as repeaters.

[edit] Roaming
Roaming between Wireless Local Area Networks

There are 2 definitions for wireless LAN roaming:

* Internal Roaming (1): The Mobile Station (MS) moves from one access point (AP) to another AP within a home network because the signal strength is too weak. An authentication server (RADIUS) assumes the re-authentication of MS via 802.1x (e.g. with PEAP). The billing of QoS is in the home network. A Mobile Station roaming from one access point to another often interrupts the flow of data between the Mobile Station and an application connected to the network. The Mobile Station, for instance, periodically monitors the presence of alternative access points (ones that will provide a better connection). At some point, based upon proprietary mechanisms, the Mobile Station decides to re-associate with an access point having a stronger wireless signal. The Mobile Station, however, may lose a connection with an access point before associating with another access point. In order to provide reliable connections with applications, the Mobile Station must generally include software that provides session persistence.[9]

* External Roaming (2): The MS(client) moves into a WLAN of another Wireless Internet Service Provider (WISP) and takes their services (Hotspot). The user can independently of his home network use another foreign network, if this is open for visitors. There must be special authentication and billing systems for mobile services in a foreign network.[10]

* Exposed terminal problem
* Fixed Wireless Data
* Hidden terminal problem
* Wireless Access Point
* Local area network
* Shared mesh
* Switched mesh
* Wireless LAN client comparison
* Wireless network
* Hotspot (Wi-Fi)
* USB
* Wireless electronic devices and health.
* Drivers: HostAP

Selasa, 03 Februari 2009

Network Address Translation (NAT)

Network Address Translation (NAT): Another way to save IP Address

Mission early Internet as a communication network is a non-profit. Initially, the Internet was designed without considering the business world. Then this is a problem now and in the future. With the large number of the Internet, in search of information and information providers, the needs will be increasingly on the Internet pengalamatan tumefy. Needs of the IP address is usually going on in the company computer network and wireless-LAN in the institution.
IP address as a means pengalamatan on the Internet become increasingly exclusive and luxury goods. Not any person can now get a valid IP address easily. Because it is required by a mechanism that can save IP address. Simple logic for saving the IP address is to share a valid IP address numbers to some other client IP. Or in other words some of the computer can access the Internet even though we only have one IP address is valid. One mechanism is provided by the Network Address Translation (NAT)

Some Basic Concepts

Before we discuss the more dust it's good we go back the basic concepts that must be understood before going to the NAT. Among them is TCP / IP, Gateway / Router, and Firewall.

TCP / IP

Which is the standard protocol and is used by almost the entire community is the Internet TCP / IP (Transmission Control Protocol / Internet Protocol). So that the computer can communicate with other computers, then the rules according to TCP / IP, the computer must have a unique address. Address is called IP address. IP Address has the following format: aaa.bbb.ccc.ddd. For example: 167.205.19.33
The most important is that to communicate on the Internet, your computer must have a legal IP address. Legal in this case means that the address is recognized by all routers in the world and know that the address does not have duplikatnya elsewhere. IP address is usually a legal contact with the InterNIC.
An internal network can use any IP address. However, to connect to the Internet, the network is still using the IP address must be legal. If the problem is not routing dibereskan (do not use legal IP address), then the system when we send the data packet to another system, the purpose of the system will not be able to restore the data packet, so the communication will not occur.
Communicate on the Internet / computer inter-network gateway required / router as a bridge that connects a network inter-knot so that the packet data can be transported to the destination.

Gateway / Router

Gateway is a computer that has a minimum of 2 network interface units to connect the 2 units or more networks. In the Internet address can be a gateway-the gateway through which to give way / route to the direction which must be passed so that the data packet to the destination. Most of the gateway routing daemon (a program to update dynamic routing table). Therefore, the gateway also functions as a router usually. Gateway / Router router can be shaped like a box in the production Cisco, 3COM, etc. or can also be a computer running Network Operating System plus routing daemon. Suppose that the PC is installed and running FreeBSD Unix program Routed or gated. However, in the Natd, routing daemon does not need to run, so just enough to install the gateway.
Because the gateway / router set the packet data traffic across the network, then it can been restrictions or security mechanisms (filtering) the data packets. This mechanism is called Firewall.

Firewalls

Firewall is actually a program that runs on the gateway / router which checks each packet of data through and compares with the rule that is applied and finally decide whether the data packet may be forwarded or rejected. The purpose is primarily as a security that protects the network from internal threats from the outside. However, in this paper is used as the basis Firewall to run Network Address Translation (NAT).
In FreeBSD, the program is run as a firewall is ipfw. Before you can run ipfw, generic kernel should be modified so that the support function of a firewall. Ipfw set the packet data traffic based on IP source, destination IP, port number, and type of protocol. To run the NAT, IPDIVERT option must be enabled in the kernel.

DIVERT (mechanism diversi package kernel)

Divert socket is the same socket with the IP usual, except that divert socket can bind to the port via the bind divert special system call. IP address in the bind is not observed, only the port number of the note. A divert socket that dibind to divert port will receive all the packets on port didiversikan by the mechanism in the kernel that is executed by the implementation of filtering and ipfw program. This mechanism will be used by the Network Address Translator.
That was some initial discussion that will take us to the next discussion of the core.

Network Address Translation (NAT)

In FreeBSD, mechanism for Network Address Translation (NAT) program run by Natd who works as a daemon. Network Address Translation Daemon (Natd) provides solutions to the problems with the economy this way hide the internal network IP address, making the package that generate in-visible in the apparently resulted from a machine that has a legal IP address. Natd provide connectivity to the outside world without having to use legal IP address in internal network.
Natd provide Network Address Translation is used to divert the socket. Natd change all packages addressed to another host so that the source IP addressnya comes from the engine Natd. For each packet that is changed according to rules, the translation table is created to record this transaction.
With NAT, to communicate that the rules should use the IP address legal, working with street dilanggar.NAT convert the IP-IP address to one or more other IP address. IP address is the converted IP address assigned to each machine in the internal network (can be any IP). IP address which is the result of conversion is located outside the internal network and the IP address is a valid legal / routable.

NAT mechanism

A TCP packet consists of header and data. Header has a number of fields in it, one of the field is important here is the MAC (Media Access Control) address of origin and destination, IP address of origin and destination, and port number of origin and destination.
A time machine to machine B, the header contains the IP packet A as the origin IP address and IP B IP address as the destination. This header also contains the port number of origin (usually chosen by the machine sending a set number of ports) and port number of a specific goal, such as port 80 (for web).
Then B receives packets on port 80 and select the port number of replies to the port number is used as a home port replaces 80 earlier. B Machine ago reverse IP address of origin & destination and port number of origin & destination in the packet header. So the situation now is IP B IP IP address of origin and a destination IP address is. B and send the packet back to A. During the open session, data packets downstream mudik use the port number is selected.
Router (the usual - without Natd) modify the MAC address field of origin & destination in the header when the me-route the package through. IP address, port number, sequence number and origin & destination is not touched at all.
NAT is also working on the basis of this. Starting with the internal translation table to make for all the internal network IP address to send the packet through. Then set the port number that the table will be used by the IP address is valid. When the packet is sent from the internal network to Natd to be out, Natd do the following:
1. Record the IP address and port of origin in the translation table
2nd Replaces the original IP packet number with the IP number itself is valid
3. Define the port number for the specific package that is sent out, put it in the translation table and replaces the original port number with the port number of this special.
When the reply packet comes back, Natd to check the destination port number. If this match with a specific port number has been set previously, then he will see the translation table and search engine in which the appropriate internal network. Once found, it will rewrite the port number and IP address with the destination IP address and port number of the original home that is used first to start the connection. Then send this package to the machine in the internal network dituju. Natd maintain the content of the table translation during the connection still open.

Sample image Natd Mechanism

nat.jpg

Differences with a Proxy

Almost similar to the NAT, a small network with a proxy can be placed several machines to access the web behind a machine that has a valid IP address. This step is also the cost savings must be compared to rent some of the ISP account and install a modem & phone connection on each machine.
However, the proxy server is not suitable for larger networks. However, adding RAM and hard disk on the proxy that the proxy is running efficiently can not be guaranteed (due to cost constraint). Moreover, the percentage of web pages that can be serviced by the proxy cache will be more in line with the decline menipisnya empty space on the hard disk, so that the use of a proxy cache is not better than the direct connection. Moreover, each connection will be at the same time to generate additional process in the proxy. Each process should use the disk I / O channel is the same, time and disk I / O channel saturated, then the bottle neck there.
NAT solution that offers a more flexible and scalable. NAT must configure the proxy / sock in each client. NAT is faster and able to handle network traffic for thousands of user-beribu simultaneously.
In addition, the address translation that is applied in the NAT, to make the cracker on the Internet may not directly attack the systems in the internal network. Intruder attack and must have access to the NAT machine before preparing to attack machines on the internal network. Important in the knowledge that, while the internal network with NAT protected, but for security problems, but only required packages filtering methods and the security of other machines in the NAT.

Case studies Installasi Natd

A company has a number of small computer and a connection to the Internet. Computers that currently have a LAN. Internet connections to its diasumskan a dedicated T1 link

The steps that must be done

1. FreeBSD installation

Provide a computer to be a Gateway. The author suggests the use of RELEASE FreeBSD 2.2.6 (Natd only way in FreeBSD 2.2.1 and above), because in addition to free the hardware requirement is not too extravagant. PC 486 with 16 MB memory and 850 MB of HD is also quite luxurious.
To find out the installation process of FreeBSD, please read the back posts in the past and Infokomputer FreeBSD manual itself.

2nd Gateway installation

2 pairs of network interfaces that this machine becomes the gateway. Network Card (NE2000 or 3COM eg) one connected to internal network and one for connection to the ISP. For example, both NE2000 Compatible. nick to the card is facing in ed0 and to draw out the card is ed1.
Make sure the option gateway = "YES" is written correctly in the rc.conf file. Or can also type the command: sysctl-w net.inet.ip.forwarding = 1

3. Firewall installation

Install a firewall on the machine IP is FreeBSD. Do is:

a. Edit the kernel source in / usr/src/sys/i386/conf
Add option-option following the kernel file.

IPFIREWALL options
IPFIREWALL_VERBOSE options
options "IPFIREWALL_VERBOSE_LIMIT = 100"
IPDIVERT options

b. Compile the kernel is
c. Enable a firewall on the rc.conf by adding

firewall = "YES"
firewall_type = "OPEN"

4. Installation Natd

The steps are as follows:
a. Download the source in its ftp://ftp.suutari.iki.fi/pub/natd
b. Unzip and untar the archive with the command
natd_1.12.tar.gz gzip-dc | tar-xvf --
c. Do make and make install in the directory produced. Type the following command:
cd natd_1.12
make
make install
d. Edit the startup file to run automatically Natd
Natd.sh Create a file in / usr / local / etc / rc.d. The contents of the file is

#! / bin / sh
/ sbin / ipfw-f flush
/ sbin / ipfw add divert 13494 ip from any to any via ed0
/ sbin / ipfw add pass all from 127.0.0.1 to 127.0.0.1
/ sbin / ipfw add pass ip from any to any
/ usr / local / sbin / natd-13494-port interface ed0

The meaning of this file is:
v Hapuskan all firewall rule
v Add feature divert the port 13494 (you can replace this with the port you want) to mendiversi packages to and from the gateway via interface ed0
v Allow all packages through the local host
v Allow all IP packets through all interfaces
v Run Natd with a daemon waiting on port 13494 via ed0 interface.

e. Reboot FreeBSD machine so that its settings can be activated.

5. Configure TCP / IP Client.

Make the IP card in FreeBSD ed0 as the gateway of each workstation, IP, each work station must be located in the same network card with ed0 on the gateway machine. Ex-beri in ed0 number ed1 IP 192.168.1.1 and 167.205.19.5, then the workstation is given the IP 192.168.1.2 s / d 192.168.1.14 mask used if 16 or 255255255240. ed1 is the interface that has a valid IP address.

After all the above steps with both the run, the client application on the Internet ready to be run via NAT.

For other cases, such as a connection to the Internet using a modem is, the mechanism is the same, live in the changed interface gateway facing out to the modem interface (tun0) and run the program for men ppp-dial his ISP. Specifically for dial-out ppp actually have their own mechanism for this is the case with option-alias. So if we run the ppp-alias option then we do not need to run Natd, because this option provides the same facility with specific Natd to dial-out.

Natd is only one way to supply the IP address is low. Given the fact that to join the Internet, seeking information host (Client) does not actually need to have a legal IP address, the IP address can be legal is reserved for hosts information provider (Server). Research continues to improve Internet performance is still to be developed. Now this model is also being developed in the new version of IP is IP version 6 (IPv6), which can accommodate more computers on the Internet. However, for the conditions now, Natd is still a powerful solution before IPv6 is applied.