Network Address Translation - NAT secrets they didn't teach you

Sdílet
Vložit
  • čas přidán 2. 06. 2024
  • Network Address Translation (NAT) is something we use every day. Many people think they know how it works, but they don't. This time Druvis looks under the hood and all becomes clear - NAT explained!
    0:00 Intro
    0:18 NAT origins
    1:26 The missing piece
    3:43 Masquerade under the hood
    5:57 Endpoint Independent Mapping
    6:30 Secret Masquerade
    7:06 Grand Summary
    8:50 Outro
  • Věda a technologie

Komentáře • 128

  • @user-zb2qm7gn7w
    @user-zb2qm7gn7w Před 5 měsíci +12

    Still missing ipv6 videos.

  • @ollisollis
    @ollisollis Před 5 měsíci +54

    Great Video, but reduce the volume of music. Please.

    • @stevenm45
      @stevenm45 Před 5 měsíci +6

      Yes, broadcast sound engineer here! Please re-mix to drop the background music by 10dB or so. Other than that I just learnt some extra stuff about NAT, thank you MT!

    • @mikkio5371
      @mikkio5371 Před 5 měsíci

      😂​😂

    • @krusher00
      @krusher00 Před 5 měsíci

      And 9:20 🎉

  • @stephanszarafinski9001
    @stephanszarafinski9001 Před 5 měsíci +1

    Great video! I like it that you explain not only the basic things, but also more in depth stuff. That way the video is interesting for both beginners and more advanced users. Good visuals too!

  • @matelotjim9035
    @matelotjim9035 Před 5 měsíci +4

    Another great video Druvis, explaining the bits that others miss.

  • @maxvideodrome4215
    @maxvideodrome4215 Před 5 měsíci

    Nice work again Mikrotik - really enjoy your products.

  • @bartomiejsikora910
    @bartomiejsikora910 Před 5 měsíci +4

    Hi MikroTik Guys. We need more videos like this. Thanks .

  • @philippeastier7657
    @philippeastier7657 Před 5 měsíci

    Thank you again, those series of videos are just great.

  • @vladislavkaras491
    @vladislavkaras491 Před 5 měsíci

    I don't know if there is anything interesting and/or complicated in bridging adapters together, but if there is, would be interesting to watch it!
    Thanks for such great video!

  • @drumaddict89
    @drumaddict89 Před 5 měsíci +19

    since MT is a routing/router company ... more videos on BGP. basics, case studies, best practices, v7 limitations and BGP in-depth with routerOS!
    BGP needs to get more love at mikrotik again.
    also MPLS/VPLS case studies or tutorials would be great in context of ROSv7 configurations

    • @chadtaylor1148
      @chadtaylor1148 Před 5 měsíci +1

      I have a /24 of public IP it was breeze to set up on VULTR with ROS6 but 7 has been a no go I absolutely cannot get it to announce. So I would very much love to see some more examples of BGP in version seven.

    • @drumaddict89
      @drumaddict89 Před 5 měsíci

      @@chadtaylor1148 not examples alone ... improvements and features which are there in v6 !!!

    • @erlonsilva3396
      @erlonsilva3396 Před 4 měsíci +1

      Currently version 7 is behaving like other manufacturers. You must have your prefix in the FIB so that it can be announced. In fact, not only that, but you need to create an addres-list with it and also send it in the out (export) filter.

  • @DeFi-Macrodosing
    @DeFi-Macrodosing Před 5 měsíci +1

    You guys are great, and your devices too. I'd never heard of you before, until I got my ATL LTE router. Amazing. I'd love to know more about customising the router's firewall.

  • @leratoradebe6438
    @leratoradebe6438 Před 5 měsíci +1

    Great video, certainly learnt something!

  • @kolifx
    @kolifx Před 5 měsíci

    Great video, concise and clear. Great follow up would be to explain how Zerotier can help if one (or both) networks is/are behind CG NAT.

  • @happy_dev
    @happy_dev Před 5 měsíci +2

    uPNP part is missing in the summary as one of the options for how to make port forwarding.
    for the next video, I would show ipv6 with examples - we don't need nat but at the same time how don't open any home device into the internet, etc.
    another topic - wifi k/v/r - what every letter means and demos with facetime/voip calls during transitions between APs

    • @mikrotik
      @mikrotik  Před 5 měsíci +1

      Not planning to do IPv6 videos at the time, but more wifi videos can be expected.

    • @happy_dev
      @happy_dev Před 5 měsíci

      @@mikrotik btw, any news about 160mhz and wifi 6e devices? And more 2.5gb/s ports, please!

  • @gcinini
    @gcinini Před 5 měsíci +1

    Great video. Also loved the VLAN series. If you guys could go deeper with the VLAN videos presenting specific scenarios to increase security in home LANs leveraging VLANS and multiple Wi-Fi networks or other similar scenarios that would be great!
    Keep up the great work.

  • @vitea1
    @vitea1 Před 5 měsíci +2

    Good video. Will be great to see video about DS-lite and IPv6

  • @black_ierax
    @black_ierax Před 5 měsíci +1

    A video going into detail for LTE, cell locking, and carrier aggregation.
    In a water bottling facility in Mount Athos, I am facing issues with my mobile operator.
    The cell tower that is located above Daphne is around 300m from the 4g router, and has power saving features enabled on high frequency bands, causing the router to drop connection to the cell tower.
    The router then establishes connection at cell towers located in Ierisos that is located around 36 ΚΜ, or at Sarti that is around 25km away, and located on the left of the dish. I am using a RBLHGR&R11e-LTE and waiting for a LHG LTE18 kit to arrive soon.

  • @jesusmedina-oi7sl
    @jesusmedina-oi7sl Před 5 měsíci +2

    Great video, make another one explaining load balancing techniques.

  • @franciscoperaltamatus
    @franciscoperaltamatus Před 4 měsíci

    amazing content, thanks for your effort!

  • @SecOps-7
    @SecOps-7 Před 5 měsíci +1

    Thanks for the great video. Would love to see a video on WiFi configuration best practices, especially Radio wave frequency best practices on Mikrotik devices. Wifi wave2 does not do great out the box without some configuration and trial and error first. 😊

  • @user-ic2fo5rg2l
    @user-ic2fo5rg2l Před 5 měsíci

    Дуже дякую за такі гарні відео 😉😊

  • @chaseendicott
    @chaseendicott Před 5 měsíci +1

    I would like to see more info about how Endpoint Independent NAT can help in a carrier grade NAT situation for ISP's that want to help open things up for customers so things aren't double NAT'ed. Setup and the benefits being highlighted would be helpful!

  • @brucemoriarty
    @brucemoriarty Před 5 měsíci +1

    amazing video and very informative :D

  • @Aestdyfyfydyyetryuoiyfghcvb
    @Aestdyfyfydyyetryuoiyfghcvb Před 5 měsíci

    Nice Music, this is a next level of video's :).
    I remember when in past, we use a Public IP on all internal PC. Police in Poland use Dual PC (one PC with Internet, second PC internal network). Those time was awesome, so big wow effect was in every category in IT.

    • @mikrotik
      @mikrotik  Před 5 měsíci

      Thanks for the cool story from the old times. We will try to make more good videos :)

  • @mnsi_darryl
    @mnsi_darryl Před 5 měsíci

    Solid intro on how NAT work, perhaps you can expand on NAT forwarding rules in RouterOS since you touched on the port knocking topic :)

    • @mikrotik
      @mikrotik  Před 5 měsíci +2

      For sure, more videos on NAT are coming.

  • @CarmineIannace
    @CarmineIannace Před 5 měsíci

    Excellent video! Paldies!

  • @salembaabbad8783
    @salembaabbad8783 Před 5 měsíci

    Thank you sir I really enjoyed the video,I hope you made a videos for network topology examples 😊

  • @Micheph
    @Micheph Před 5 měsíci

    Saved me rereads. Do not forget to remind us who are just users why it is important to read Mikrotik block diagrams.

  • @SavroRus
    @SavroRus Před 5 měsíci

    thank you for clear explanation 🙏

  • @MohammedBizzan
    @MohammedBizzan Před 5 měsíci +2

    Hey Mikrotik, will we get an Apple Silicion native winbox app?

  • @kiranrajr
    @kiranrajr Před 5 měsíci +6

    Hi Team, The Video was amazing and very helpful for us. Can you make a video explaining CG NAT in MikroTik?

    • @mikrotik
      @mikrotik  Před 5 měsíci +11

      For sure, probably after the holidays.

    • @kiranrajr
      @kiranrajr Před 5 měsíci +1

      @@mikrotik Thank You 🙏🏻

  • @anakinskywalker8624
    @anakinskywalker8624 Před 5 měsíci

    Thank you for this video topic :)

  • @SoranEngineer
    @SoranEngineer Před 5 měsíci

    great video thank you so much for explain

  • @jiucaibox
    @jiucaibox Před 5 měsíci

    This video is so magnificent, I hope it can be translate to various languages.

  • @frankh.4420
    @frankh.4420 Před 5 měsíci

    Thank you for that informative video. What about ipv6 fundamentials and subnetting?

  • @chadtaylor1148
    @chadtaylor1148 Před 5 měsíci +1

    I really enjoy the deeper videos where they deep dive into a topic, explain things, programming examples etc. Dont get me wrong I don't want the fun ones to go away but I would love a weekly series where we could expect to see a technical video every Tuesday or something like that.

  • @mikkio5371
    @mikkio5371 Před 5 měsíci +1

    Network trip was doing some great vidoe on firewall though too

  • @chechitogmail
    @chechitogmail Před 5 měsíci +1

    a clarification on NAT action=same and the option not-by-dst also, will be nice thank you, good video

  • @jeytis72
    @jeytis72 Před 5 měsíci

    I'd like to see more videos about routing tables, routing rules, and firewall mangle marking. Thanks

  • @nicolaperotto1933
    @nicolaperotto1933 Před 4 měsíci

    The music is disturbing and confusing: some people here has to concentrare to understand what you say.
    The video is very well done, interesting and informative. Thanks

  • @mikkio5371
    @mikkio5371 Před 5 měsíci

    Port address translation. The last two is what I don't know about ( harping & carrier ) . Druvis is back !! Being a while .

  • @pmcmar
    @pmcmar Před 5 měsíci

    Cool video. Maybe you could add the OSI model layer's namely the transport layer.. but it could get confusing 😅

  • @gregmc3957
    @gregmc3957 Před 5 měsíci

    Good video.
    Can you do a video on MSTP where vlans or redundant links between devices occur.

  • @criticalmoorhen
    @criticalmoorhen Před 5 měsíci

    Video idea - CAKE and queue trees. There is also lack of documentation from your side on Cake, so I guess video would do it. Personally I expect you to show off how to setup up CAKE with proper parameters and set up queue tree, all for home/homelab users. I would like to see general recommendations on what kind of queues you might recommend, how to prioritize primary network and give "leftover" traffic to guest network or seedbox. Also - great video!

    • @criticalmoorhen
      @criticalmoorhen Před 5 měsíci

      Another idea - how to properly set up hairpin NAT. It's one of those tricky areas to set up correctly and no "right" answer in forums too. :)

    • @mikrotik
      @mikrotik  Před 5 měsíci

      We have a video about that czcams.com/video/1I5FywY6opQ/video.htmlsi=YvZBr2ygOkkPilp0

  • @nday345
    @nday345 Před 5 měsíci

    Thank you for the video! Tell us how SNAT works for protocols other than TCP and UDP, for example ICMP, GRE, IPIP, etc. How does a router keep track of connections when several hosts on the local network behind a NAT send ICMP requests to the same host on the Internet? How does he understand which host on the local network to return the ICMP reply to?

    • @mikrotik
      @mikrotik  Před 5 měsíci +1

      Valid questions, there will be something short on ICMP and NAT.

  • @user-fs4cx2uk4r
    @user-fs4cx2uk4r Před 5 měsíci

    Great video!!

  • @renekuhl7934
    @renekuhl7934 Před 5 měsíci

    Good Video.. Kepp it up Guys!

  • @dummydummydummy7568
    @dummydummydummy7568 Před 5 měsíci +2

    Hello,
    Very interesting video but could you please make other videos that delve deeper into the types of nat he showed?
    Thank you

  • @user-pn4qz7dg2l
    @user-pn4qz7dg2l Před 5 měsíci

    RouterOS Firewall Mangle is fantastic. Please create new videos about different usages of Mangles and firewall rules like blocking Ads, doubling internet speed by using two ISPs, or even connecting to a website using a specific VPN interface.
    I also need to know how to monitor and debug the routing rules, connections, interfaces, and packets.
    Thank you for the great videos.

  • @aligenawi
    @aligenawi Před 5 měsíci +1

    grate work , if you lower or remove the music during the talking it will make it easy to concentrate and follow up the topic .

  • @tannoy
    @tannoy Před 5 měsíci +1

    Great video. Would be good to add how to set this up on RouterOs. Thanks.

  • @tlturner3
    @tlturner3 Před 5 měsíci

    Great video. It would be be to explain a common misconception to those new to routing and that confusing source NAT with static NAT and destination NAT dynamic NAT.

    • @mikrotik
      @mikrotik  Před 5 měsíci

      Ok, we will do more RouterOS specific NAT videos!

  • @pavelsmarhels8868
    @pavelsmarhels8868 Před 5 měsíci

    It would be great to hear something about (diff/incr) config backup of bunch of mikrotiks. With products like rancid + git.

  • @phil2768
    @phil2768 Před 5 měsíci

    Thank you!

  • @agentbayabas
    @agentbayabas Před 4 měsíci

    can you create an details like that on how port forwarding works i want like that with visualization

  • @Grmreeper100
    @Grmreeper100 Před 5 měsíci

    Thank you for the greate work

  • @hristobarbolov5953
    @hristobarbolov5953 Před 5 měsíci +1

    An idea for a video - IPv6 and how to configure it

  • @cruronet
    @cruronet Před 5 měsíci

    Hello i have a issue i have a server on my house port xxxx but when i turn of the server i pop up the router UI.... how do i prevent that happening

  • @jfernandez76
    @jfernandez76 Před 5 měsíci

    For a next topic, please, consider talking about cross-vlan mDNS.

  • @matejsojka6683
    @matejsojka6683 Před 5 měsíci +1

    make another video and show how to configure those nats explained here on mikrotik routers.

    • @mikrotik
      @mikrotik  Před 5 měsíci +1

      There will be videos on all of them. We have already covered port-forwarding and Hairpin NAT in the past, however.

  • @MartinEscudero
    @MartinEscudero Před 5 měsíci

    HEY! When will routers have harpin nat activated by default and a DDNS integrated client for no-ip or other providers? Thanks

    • @mikrotik
      @mikrotik  Před 5 měsíci

      Only a small percentage of customers will use Hairpin NAT, so there is no need to do the extra configuration for everyone. DDNS is integrated and available for everyone, just enable it in the IP Cloud section.

  • @examen1996
    @examen1996 Před 5 měsíci

    Always loved mikrotik but never had one, really looking at a rb5009 , a device that i already recomended to a friend who bought it and is extremely happy with it.
    One great video ideea would be a entry 10gb home network for home labs, mikrotik(switch, router) equipment only.
    While I love openwrt, i cant help but wishing the quality of mikrotik hardware for my network .
    Regards

  • @HarishSharmaDelhi
    @HarishSharmaDelhi Před 5 měsíci

    I am small hotel owner and I would love to see a video that will explain how hotspot and usermanager work on RouterOS 7

  • @user-wy2ys7eo8j
    @user-wy2ys7eo8j Před 5 měsíci

    chateau 5G ax update 7.13 后,找不到wlan1 wlan2 怎么解决?

  • @rihardsbimanis8390
    @rihardsbimanis8390 Před 5 měsíci

    Why i cant port forward with BITE mobile network? Mikrotik LTE device shows private address, so maybe they are using NAT and blocking port 80?

    • @mikrotik
      @mikrotik  Před 5 měsíci +2

      Mobile operators usually use CG NAT and other techniques, so for port-forwarding to work they would have to configure it at their end.

    • @user-km4tt4ok8t
      @user-km4tt4ok8t Před 5 měsíci

      Rihards, did you buy from BITE static public IP address?

  • @Graham_Rule
    @Graham_Rule Před 5 měsíci +1

    Great content. Terrible background 'music' made it difficult to concentrate on the words though.

  • @yingpan6436
    @yingpan6436 Před 5 měsíci

    hello miktorik, how to nat dstnat range port to range ip on mikrotik router ?

    • @mikrotik
      @mikrotik  Před 5 měsíci

      We will cover dstnat in more detail :)

  • @apruszko
    @apruszko Před 5 měsíci

    Dear Dru, please create some video about iot mqtt with SSL and safe configuration (now: mqtt credentials in config are in plain text, reading this config, an intruder can break our mqtt broker, please see that certificates and keys are no stored in config, I mean "/export teres" does not show critical information). Thanks for previous video - those helps me buy many mikrotik hardwares 😊

    • @mikrotik
      @mikrotik  Před 5 měsíci +1

      Like with other sensitive data on your router - the key is to use strong user passwords and not hand them out to anyone you don't trust.

  • @MateusProvesi
    @MateusProvesi Před 4 měsíci

    Please talk about IPv6.

  • @meddle999
    @meddle999 Před 5 měsíci

    IPv6 security topics please

  • @rusnyasosat
    @rusnyasosat Před 5 měsíci +1

    Nice

  • @userbanned4419
    @userbanned4419 Před 5 měsíci

    ну на вас давно подписан, по этому нашел)

  • @ssimeonovbg
    @ssimeonovbg Před 5 měsíci

    More info about CGnat please

    • @mikrotik
      @mikrotik  Před 5 měsíci

      Sure, after the holidays.

  • @zanydaproduction7645
    @zanydaproduction7645 Před 5 měsíci

    Спасибо. Если добавите русские субтитры будет вообще фантастически❤. Mikrotik 👍🤟

    • @zanydaproduction7645
      @zanydaproduction7645 Před 4 měsíci

      Хотя если смотреть через Яндекс браузер с переводом нейросети на РУССКИЙ то воОбще Агонь. 😀

  • @sebastiankutter3630
    @sebastiankutter3630 Před 4 měsíci

    I have an idea for a video series: Let's create our own ISP with MikroTik, including CGNAT, PPPoE, and so on.

    • @mikrotik
      @mikrotik  Před 4 měsíci

      Depends on the region in the world. PPPoE is not used around here. I guess common ISP setups in Latvia would not be possible in your region.

    • @sebastiankutter3630
      @sebastiankutter3630 Před 4 měsíci

      @@mikrotik In Germany you usually login to your isp with pppoe

    • @mikrotik
      @mikrotik  Před 4 měsíci

      It's very sad, I'm sorry

    • @sebastiankutter3630
      @sebastiankutter3630 Před 4 měsíci

      @@mikrotik How does it work in Latvia?

  • @phcsmile
    @phcsmile Před 5 měsíci

    How to use Mikrotik NAT or another. Trick. To avoid starlink detect internet sharing and stop throttle and tarping connection - bandwidth

  • @cruelyamagaming7096
    @cruelyamagaming7096 Před 5 měsíci

    When 5G sim router launching in india..?

  • @emanuelcoc
    @emanuelcoc Před 5 měsíci

    Muito bom

  • @user-vy4sf5fl3n
    @user-vy4sf5fl3n Před 5 měsíci +2

    make bgp video settings on v7 mikrotik

    • @mikrotik
      @mikrotik  Před 5 měsíci +1

      In the plans already :)

  • @next3138
    @next3138 Před 5 měsíci

    pls fix a problem ipv6 dhcp bad server duid 6660, ignore it

  • @sabitzubairzayn6945
    @sabitzubairzayn6945 Před 5 měsíci

    Make a proper video about CGNAT if possible.

  • @notDacian
    @notDacian Před 5 měsíci +3

    The background music is way to loud!

  • @user-pz3tq1wj1z
    @user-pz3tq1wj1z Před 4 měsíci

    ros The download speed is so slow

  • @QueeeeenZ
    @QueeeeenZ Před 5 měsíci

    You are pronouncing the word ”allow” wrongly. The emphasis is on the last syllable.

  • @userbanned4419
    @userbanned4419 Před 5 měsíci

    основные вопросы:
    по видео всё понятно, лучше туториалы делайте как настраивать оборудование конечным клиентам, тк ваше оборудование с среднем сигменте для конечного пользователя.

  • @husseinadil6290
    @husseinadil6290 Před 5 měsíci

    The music has ruined the benefit of this video. Please make the background music calm and volume it down as much as possible. We are here to gain knowledge from you. Music is our last concern.

    • @mikrotik
      @mikrotik  Před 5 měsíci

      We will try to do better.

  • @davidz1264
    @davidz1264 Před 5 měsíci +3

    What is NAT?
    It‘s EVIL 🙈

  • @kiharamuchangi4228
    @kiharamuchangi4228 Před měsícem

    Bridging Video

  • @wisperinternetinalambrico8590

    el nat deberia desaparecer para eso está ipv6