Re: NAT - Network Address Translation

From: Ian Gregory (I.H.Gregory@herts.ac.uk)
Date: 06/14/02


From: I.H.Gregory@herts.ac.uk (Ian Gregory)
Date: 14 Jun 2002 16:37:23 GMT

In article <34oO8.8$Pd6.151@paloalto-snr1.gtei.net>, Barry Margolin wrote:
>In article <slrnagj085.b13.news@news.jors.net>,
>Juergen P. Meier <news-reply@jors.net> wrote:
>>A router that performs NAT does this inside the NAT code. He probably
>>uses some tables that tell it what to NAT and how.
>
>Exactly. Distinguishing between the operations that are done in the
>"routing table" and those that are done in "with an[sic] daemon" is
>inappropriate when we're talking about NATs in general, not specific
>implementations.
>
>The fact that Bernd Eckenfels felt it necessary to bring that up made me
>think that he was referring to something other than generic NATs.

Fair enough. My own contribution to this thread was from the point
of view of someone running IP Filter (on Solaris 8) where there is
a "fastroute" keyword. Note the following passage from the HOWTO
(when talking about the use of fastroute to bypass the IP stack
and avoid a TTL decrement);

"It should be noted, however, that most Unix kernels (and certainly
the ones that ipfilter runs on) have far more eficient routing code
than what exists in ipfilter, and this keyword should not be thought
of as a way to improve the operating speed of your firewall, and
should only be used in places where stealth is an issue."

This is what lead me to make a mental distinction between routing
(kernel) and natting (ipfilter). It is possible that it is not
relevent to generic NATs.

-- 
Ian Gregory
Systems and Applications Manager
Learning and Information Services
University of Hertfordshire



Relevant Pages

  • Re: NAT - Network Address Translation
    ... >>A router that performs NAT does this inside the NAT code. ... the ones that ipfilter runs on) have far more eficient routing code ... than what exists in ipfilter, and this keyword should not be thought ...
    (comp.security.unix)
  • Re: NAT - Network Address Translation
    ... >A router that performs NAT does this inside the NAT code. ... *** DON'T SEND TECHNICAL QUESTIONS DIRECTLY TO ME, post them to newsgroups. ...
    (comp.security.unix)
  • Re: NAT - Network Address Translation
    ... >A router that performs NAT does this inside the NAT code. ... *** DON'T SEND TECHNICAL QUESTIONS DIRECTLY TO ME, post them to newsgroups. ...
    (comp.security.unix)
  • Re: Setting up an Indy with DHCP and cable modem?...
    ... Can't figure out passive ftp yet. ... ipfilter doing the NAT stuff. ... so I have to reset the static route and run proclaim again. ...
    (comp.sys.sgi.misc)
  • IPFilter problem revisited
    ... I couple of days ago I posted my problem regarding ipfilter and NAT ... that seemed not to work for TCP but for ICMP/UDP for version 3.4.35 ... I hope that Sun's 4.0.2 built into Sol10 ipfilter doesn't show any ...
    (comp.unix.solaris)