4.3.5 |
Network Address Translation (NAT) |
Network Address Translation (NAT) |
| NAT is the conversion of IP addresses in the LAN for the Internet. NAT can be enabled and disabled in HiPath 3000/5000. |
| Certain services - such as VoIP or video telephony - embed subscribers' IP addresses in their data packets, however, instead of just noting them in the packet headers. These services are only compatible with NAT within a VPN or require the use of additional protocols (for example, STUN) or infrastructure components to bypass problems with NAT (=NAT Traversal) for connections to an Internet telephony provider. |
Operation behind a router/firewall in NAT traversal |
| For operation behind a router/firewall: If an ITSP provides a STUN server for NAT traversal, none of the routers implemented supports the "symmetric NAT" variant. The use of STUN protocols is not required and the firewall reconfiguration is not necessary if the ITSPs perform NAT traversal over infrastructure components in the provider network, such as, session border controllers (SBC). "SIP-aware" firewalls also feature a NAT traversal function. |
Simple Traversal of UDP over NATs (STUN) |
| STUN is a simple client/server-based network protocol designed to identify the existence of NAT firewalls and routers. A central STUN client on the first HG 1500 V3.0 (signaling gateway) connects with a STUN server at the ITSP. The STUN server provides information about how the Internet connection is perceived externally. HiPath 3000/5000 uses this information to send packets to an ITSP or called party in the Internet to ensure that even HiPath 3000/5000 systems behind a NAT device can be reached from the Internet. The settings for an upstream NAT firewall or a NAT router do not have to be changed for this. |
| A signaling gateway can perform STUN requests on behalf of media gateways. The mechanism that sends IP packages on behalf of other devices is known as "IP Spoofing". |
| By deliberately using special filters, some network infrastructure components can check the assignment of incoming packets and take the necessary action if the assignment is incorrect, for example, trigger an alarm (e-mail), reject the packet or even block the port (for example, by SNMP access to switches). Network administrators must configure exceptions so that the STUN protocol can be used for NAT traversal even in such an environment. |
HG 1500 |
| HG 1500 is operated in the LAN behind external routers with firewall or NAT functionality. |
| HiPath 3000/5000 V9, Feature Description, Issue 7 | up ![]() |
|
![]() |
||
| Disclaimer & Copyright | ID: P31003H3590F100017618 | 2012-06-25 |