Selasa, 03 Februari 2009

Network Address Translation (NAT)

Network Address Translation (NAT): Another way to save IP Address

Mission early Internet as a communication network is a non-profit. Initially, the Internet was designed without considering the business world. Then this is a problem now and in the future. With the large number of the Internet, in search of information and information providers, the needs will be increasingly on the Internet pengalamatan tumefy. Needs of the IP address is usually going on in the company computer network and wireless-LAN in the institution.
IP address as a means pengalamatan on the Internet become increasingly exclusive and luxury goods. Not any person can now get a valid IP address easily. Because it is required by a mechanism that can save IP address. Simple logic for saving the IP address is to share a valid IP address numbers to some other client IP. Or in other words some of the computer can access the Internet even though we only have one IP address is valid. One mechanism is provided by the Network Address Translation (NAT)

Some Basic Concepts

Before we discuss the more dust it's good we go back the basic concepts that must be understood before going to the NAT. Among them is TCP / IP, Gateway / Router, and Firewall.

TCP / IP

Which is the standard protocol and is used by almost the entire community is the Internet TCP / IP (Transmission Control Protocol / Internet Protocol). So that the computer can communicate with other computers, then the rules according to TCP / IP, the computer must have a unique address. Address is called IP address. IP Address has the following format: aaa.bbb.ccc.ddd. For example: 167.205.19.33
The most important is that to communicate on the Internet, your computer must have a legal IP address. Legal in this case means that the address is recognized by all routers in the world and know that the address does not have duplikatnya elsewhere. IP address is usually a legal contact with the InterNIC.
An internal network can use any IP address. However, to connect to the Internet, the network is still using the IP address must be legal. If the problem is not routing dibereskan (do not use legal IP address), then the system when we send the data packet to another system, the purpose of the system will not be able to restore the data packet, so the communication will not occur.
Communicate on the Internet / computer inter-network gateway required / router as a bridge that connects a network inter-knot so that the packet data can be transported to the destination.

Gateway / Router

Gateway is a computer that has a minimum of 2 network interface units to connect the 2 units or more networks. In the Internet address can be a gateway-the gateway through which to give way / route to the direction which must be passed so that the data packet to the destination. Most of the gateway routing daemon (a program to update dynamic routing table). Therefore, the gateway also functions as a router usually. Gateway / Router router can be shaped like a box in the production Cisco, 3COM, etc. or can also be a computer running Network Operating System plus routing daemon. Suppose that the PC is installed and running FreeBSD Unix program Routed or gated. However, in the Natd, routing daemon does not need to run, so just enough to install the gateway.
Because the gateway / router set the packet data traffic across the network, then it can been restrictions or security mechanisms (filtering) the data packets. This mechanism is called Firewall.

Firewalls

Firewall is actually a program that runs on the gateway / router which checks each packet of data through and compares with the rule that is applied and finally decide whether the data packet may be forwarded or rejected. The purpose is primarily as a security that protects the network from internal threats from the outside. However, in this paper is used as the basis Firewall to run Network Address Translation (NAT).
In FreeBSD, the program is run as a firewall is ipfw. Before you can run ipfw, generic kernel should be modified so that the support function of a firewall. Ipfw set the packet data traffic based on IP source, destination IP, port number, and type of protocol. To run the NAT, IPDIVERT option must be enabled in the kernel.

DIVERT (mechanism diversi package kernel)

Divert socket is the same socket with the IP usual, except that divert socket can bind to the port via the bind divert special system call. IP address in the bind is not observed, only the port number of the note. A divert socket that dibind to divert port will receive all the packets on port didiversikan by the mechanism in the kernel that is executed by the implementation of filtering and ipfw program. This mechanism will be used by the Network Address Translator.
That was some initial discussion that will take us to the next discussion of the core.

Network Address Translation (NAT)

In FreeBSD, mechanism for Network Address Translation (NAT) program run by Natd who works as a daemon. Network Address Translation Daemon (Natd) provides solutions to the problems with the economy this way hide the internal network IP address, making the package that generate in-visible in the apparently resulted from a machine that has a legal IP address. Natd provide connectivity to the outside world without having to use legal IP address in internal network.
Natd provide Network Address Translation is used to divert the socket. Natd change all packages addressed to another host so that the source IP addressnya comes from the engine Natd. For each packet that is changed according to rules, the translation table is created to record this transaction.
With NAT, to communicate that the rules should use the IP address legal, working with street dilanggar.NAT convert the IP-IP address to one or more other IP address. IP address is the converted IP address assigned to each machine in the internal network (can be any IP). IP address which is the result of conversion is located outside the internal network and the IP address is a valid legal / routable.

NAT mechanism

A TCP packet consists of header and data. Header has a number of fields in it, one of the field is important here is the MAC (Media Access Control) address of origin and destination, IP address of origin and destination, and port number of origin and destination.
A time machine to machine B, the header contains the IP packet A as the origin IP address and IP B IP address as the destination. This header also contains the port number of origin (usually chosen by the machine sending a set number of ports) and port number of a specific goal, such as port 80 (for web).
Then B receives packets on port 80 and select the port number of replies to the port number is used as a home port replaces 80 earlier. B Machine ago reverse IP address of origin & destination and port number of origin & destination in the packet header. So the situation now is IP B IP IP address of origin and a destination IP address is. B and send the packet back to A. During the open session, data packets downstream mudik use the port number is selected.
Router (the usual - without Natd) modify the MAC address field of origin & destination in the header when the me-route the package through. IP address, port number, sequence number and origin & destination is not touched at all.
NAT is also working on the basis of this. Starting with the internal translation table to make for all the internal network IP address to send the packet through. Then set the port number that the table will be used by the IP address is valid. When the packet is sent from the internal network to Natd to be out, Natd do the following:
1. Record the IP address and port of origin in the translation table
2nd Replaces the original IP packet number with the IP number itself is valid
3. Define the port number for the specific package that is sent out, put it in the translation table and replaces the original port number with the port number of this special.
When the reply packet comes back, Natd to check the destination port number. If this match with a specific port number has been set previously, then he will see the translation table and search engine in which the appropriate internal network. Once found, it will rewrite the port number and IP address with the destination IP address and port number of the original home that is used first to start the connection. Then send this package to the machine in the internal network dituju. Natd maintain the content of the table translation during the connection still open.

Sample image Natd Mechanism

nat.jpg

Differences with a Proxy

Almost similar to the NAT, a small network with a proxy can be placed several machines to access the web behind a machine that has a valid IP address. This step is also the cost savings must be compared to rent some of the ISP account and install a modem & phone connection on each machine.
However, the proxy server is not suitable for larger networks. However, adding RAM and hard disk on the proxy that the proxy is running efficiently can not be guaranteed (due to cost constraint). Moreover, the percentage of web pages that can be serviced by the proxy cache will be more in line with the decline menipisnya empty space on the hard disk, so that the use of a proxy cache is not better than the direct connection. Moreover, each connection will be at the same time to generate additional process in the proxy. Each process should use the disk I / O channel is the same, time and disk I / O channel saturated, then the bottle neck there.
NAT solution that offers a more flexible and scalable. NAT must configure the proxy / sock in each client. NAT is faster and able to handle network traffic for thousands of user-beribu simultaneously.
In addition, the address translation that is applied in the NAT, to make the cracker on the Internet may not directly attack the systems in the internal network. Intruder attack and must have access to the NAT machine before preparing to attack machines on the internal network. Important in the knowledge that, while the internal network with NAT protected, but for security problems, but only required packages filtering methods and the security of other machines in the NAT.

Case studies Installasi Natd

A company has a number of small computer and a connection to the Internet. Computers that currently have a LAN. Internet connections to its diasumskan a dedicated T1 link

The steps that must be done

1. FreeBSD installation

Provide a computer to be a Gateway. The author suggests the use of RELEASE FreeBSD 2.2.6 (Natd only way in FreeBSD 2.2.1 and above), because in addition to free the hardware requirement is not too extravagant. PC 486 with 16 MB memory and 850 MB of HD is also quite luxurious.
To find out the installation process of FreeBSD, please read the back posts in the past and Infokomputer FreeBSD manual itself.

2nd Gateway installation

2 pairs of network interfaces that this machine becomes the gateway. Network Card (NE2000 or 3COM eg) one connected to internal network and one for connection to the ISP. For example, both NE2000 Compatible. nick to the card is facing in ed0 and to draw out the card is ed1.
Make sure the option gateway = "YES" is written correctly in the rc.conf file. Or can also type the command: sysctl-w net.inet.ip.forwarding = 1

3. Firewall installation

Install a firewall on the machine IP is FreeBSD. Do is:

a. Edit the kernel source in / usr/src/sys/i386/conf
Add option-option following the kernel file.

IPFIREWALL options
IPFIREWALL_VERBOSE options
options "IPFIREWALL_VERBOSE_LIMIT = 100"
IPDIVERT options

b. Compile the kernel is
c. Enable a firewall on the rc.conf by adding

firewall = "YES"
firewall_type = "OPEN"

4. Installation Natd

The steps are as follows:
a. Download the source in its ftp://ftp.suutari.iki.fi/pub/natd
b. Unzip and untar the archive with the command
natd_1.12.tar.gz gzip-dc | tar-xvf --
c. Do make and make install in the directory produced. Type the following command:
cd natd_1.12
make
make install
d. Edit the startup file to run automatically Natd
Natd.sh Create a file in / usr / local / etc / rc.d. The contents of the file is

#! / bin / sh
/ sbin / ipfw-f flush
/ sbin / ipfw add divert 13494 ip from any to any via ed0
/ sbin / ipfw add pass all from 127.0.0.1 to 127.0.0.1
/ sbin / ipfw add pass ip from any to any
/ usr / local / sbin / natd-13494-port interface ed0

The meaning of this file is:
v Hapuskan all firewall rule
v Add feature divert the port 13494 (you can replace this with the port you want) to mendiversi packages to and from the gateway via interface ed0
v Allow all packages through the local host
v Allow all IP packets through all interfaces
v Run Natd with a daemon waiting on port 13494 via ed0 interface.

e. Reboot FreeBSD machine so that its settings can be activated.

5. Configure TCP / IP Client.

Make the IP card in FreeBSD ed0 as the gateway of each workstation, IP, each work station must be located in the same network card with ed0 on the gateway machine. Ex-beri in ed0 number ed1 IP 192.168.1.1 and 167.205.19.5, then the workstation is given the IP 192.168.1.2 s / d 192.168.1.14 mask used if 16 or 255255255240. ed1 is the interface that has a valid IP address.

After all the above steps with both the run, the client application on the Internet ready to be run via NAT.

For other cases, such as a connection to the Internet using a modem is, the mechanism is the same, live in the changed interface gateway facing out to the modem interface (tun0) and run the program for men ppp-dial his ISP. Specifically for dial-out ppp actually have their own mechanism for this is the case with option-alias. So if we run the ppp-alias option then we do not need to run Natd, because this option provides the same facility with specific Natd to dial-out.

Natd is only one way to supply the IP address is low. Given the fact that to join the Internet, seeking information host (Client) does not actually need to have a legal IP address, the IP address can be legal is reserved for hosts information provider (Server). Research continues to improve Internet performance is still to be developed. Now this model is also being developed in the new version of IP is IP version 6 (IPv6), which can accommodate more computers on the Internet. However, for the conditions now, Natd is still a powerful solution before IPv6 is applied.

Tidak ada komentar:

Posting Komentar