Understanding Netopia NAT Behavior C-3

When the Netopia R9100 receives this IP packet, it cannot simply forward it to the WAN interface and the Internet since the IP addresses on the LAN interface are not valid or globally unique for the Internet. Instead, the Netopia R9100 has to change the IP packet to reflect the IP address that was acquired on the WAN interface from the ISP.

The Netopia R9100 will first substitute the source IP address with the IP address that was acquired on the WAN interface, which in this case is 200.1.1.40. Next the Netopia R9100 will substitute the source TCP or UDP port with a TCP or UDP port from within a specified range maintained within the Netopia R9100. And finally the modified IP packet's checksum is recalculated (as specified in RFC 1631) and the packet is transmitted across the WAN interface to its destination, the WWW server on the Internet.

If the send and response IP packets were drawn out, this process would look like the following:

WWW Server

ISP Router

Netopia Router

 

Workstation A

163.176.4.32

200.1.1.1

 

LAN: 192.168.5.1

192.168.5.2

 

 

 

WAN: 200.1.1.40

 

 

 

 

 

 

 

Router

 

 

Netopia

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

ISP Router to WWW

Netopia to ISP Router

 

 

Wkstn A to Netopia

Src IP: 200.1.1.40

Src IP: 200.1.1.40

 

 

Src IP: 192.168.5.2

Dst IP: 163.176.4.32

Dst IP: 163.176.4.32

 

 

Dst IP: 163.176.4.32

Src Port: 5001

Src Port: 5001

 

 

Src Port: 400

Dst Port: 80

Dst Port: 80

 

 

Dst Port: 80

WWW to ISP Router

ISP Router to Netopia

Netopia to Wkstn A

Src IP: 163.176.4.32

Src IP: 163.176.4.32

Src IP: 163.176.4.32

Dst IP: 200.1.1.40

Dst IP: 200.1.1.40

Dst IP: 192.168.5.2

Src Port: 80

Src Port: 80

Src Port: 80

Dst Port: 5001

Dst Port: 5001

Dst Port: 400

As you can see, the IP packet from Workstation A is sent to the Netopia R9100 and the source IP address is substituted with 200.1.1.40 and the source port is substituted with 5001, then the IP packet checksum is recalculated. When this modified packet reaches the WWW server on the Internet, the WWW server responds and sends the IP packet back to destination IP address 200.1.1.40 and destination port 5001.

When the Netopia R9100 receives this IP packet from the WWW server, the Netopia R9100 replaces the destination IP address with 192.168.5.2, the address for Workstation A. The port is changed back to 400, the IP packet checksum is recalculated, and the IP packet is sent to Workstation A on the Netopia R9100s LAN interface.

Page 211
Image 211
Farallon Communications R9100 manual Understanding Netopia NAT Behavior C-3

R9100 specifications

Farallon Communications R9100 is a high-performance network device designed to meet the demanding needs of modern telecommunications. This robust system specializes in delivering reliable, efficient, and scalable solutions for various networking environments. Its architectural design integrates cutting-edge technologies that enhance performance while ensuring compatibility with existing infrastructure.

One of the standout features of the R9100 is its advanced routing capabilities. Equipped with powerful processors, it supports multiple routing protocols, including OSPF, BGP, and EIGRP. This flexibility allows network administrators to optimize data flow and maintain seamless connectivity across diverse network topologies. The R9100 also includes sophisticated Quality of Service (QoS) mechanisms, enabling prioritization of critical traffic, which is essential for latency-sensitive applications.

Another significant aspect of the R9100 is its support for various interfaces. Whether organizations require Ethernet, fiber, or wireless connections, the R9100 accommodates a broad range of interface options. This versatility ensures that it can be deployed in various environments, from large enterprise networks to smaller branch offices.

Security is a crucial consideration in today’s networking landscape, and the R9100 addresses this with built-in security features. These include stateful firewall capabilities, Intrusion Detection System (IDS), and comprehensive Virtual Private Network (VPN) support. Such features allow organizations to safeguard sensitive data and maintain compliance with industry regulations.

The R9100 also prioritizes ease of management. With a user-friendly interface and robust monitoring tools, network administrators can easily configure and manage the device. This capability facilitates rapid troubleshooting and performance tuning, ensuring minimal downtime and optimal user experience.

Energy efficiency is an additional characteristic that sets the R9100 apart from its competitors. Designed with eco-friendly technologies, it minimizes power consumption while maximizing output, making it an ideal choice for organizations looking to reduce their carbon footprint.

In conclusion, Farallon Communications R9100 stands out as a versatile and powerful network device that meets the complexities of modern telecommunications. With its advanced routing features, robust security measures, varied interface options, and energy-efficient design, the R9100 is a formidable player in the networking landscape. Organizations can rely on this solution to enhance their network performance and evolve alongside their growing technological needs.