2 cissp ® Official Study Guide Eighth Edition



Download 19,3 Mb.
Pdf ko'rish
bet512/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   508   509   510   511   512   513   514   515   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Private IP Addresses 
The use of NAT has proliferated recently because of the increased scarcity of public IP 
addresses and security concerns. With only roughly 4 billion addresses (2 
32
) available 
in IPv4, the world has simply deployed more devices using IP than there are unique IP 
addresses available. Fortunately, the early designers of the internet and TCP/IP had good 
foresight and put aside a few blocks of addresses for private, unrestricted use. These IP 
addresses, commonly called the private IP addresses, are defi ned in RFC 1918. They are as 
follows: 

10.0.0.0–10.255.255.255 (a full Class A range) 

172.16.0.0–172.31.255.255 (16 Class B ranges) 

192.168.0.0–192.168.255.255 (256 Class C ranges)
Can’t NAT Again!
On several occasions we’ve needed to re-NAT an already NATed network. This might 
occur in the following situations: 

You need to make an isolated subnet within a NATed network and attempt to do 
so by connecting a router to host your new subnet to the single port offered by the 
existing network. 

You have a DSL or cable modem that offers only a single connection but you have 
multiple computers or want to add wireless to your environment.


Network Address Translation 
551
By connecting a NAT proxy router or a wireless access point, you are usually attempting 
to re-NAT what was NATed to you initially. One confi guration setting that can either 
make or break this setup is the IP address range in use. It is not possible to re-NAT the 
same subnet. For example, if your existing network is offering 192.168.1.x addresses, 
then you cannot use that same address range in your new NATed subnet. So change the 
confi guration of your new router/WAP to perform NAT on a slightly different address 
range, such as 192.168.5.x, so you won’t have the confl ict. This seems obvious, but it is 
quite frustrating to troubleshoot the unwanted result without this insight.
All routers and traffi c-directing devices are confi gured by default not to forward traffi c 
to or from these IP addresses. In other words, the private IP addresses are not routed by 
default. Thus, they cannot be directly used to communicate over the internet. However, 
they can be easily used on private networks where routers are not employed or where slight 
modifi cations to router confi gurations are made. Using private IP addresses in conjunction 
with NAT greatly reduces the cost of connecting to the internet by allowing fewer public IP 
addresses to be leased from an ISP. 
Attempting to use these private IP addresses directly on the internet is 
futile because all publicly accessible routers will drop data packets con-
taining a source or destination IP address from these RFC 1918 ranges.

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   508   509   510   511   512   513   514   515   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish