From How to Cheat at VoIP Security

A Word about Network Address Translation and Firewalls

When the Internet began, the creators didn t envision the type of growth that we are experiencing today. During the last 10 years, the number of hosts on the Internet increased by more than a factor of 50. 1 In order for each Internet device, or host, to communicate on the Internet, it must have a unique internet protocol (IP) address. The addressing scheme for the Internet allowed for billions of IP addresses, but now most of them are allocated.

The Internet s popularity results in a maximum number of available IP addresses. Homes and offices around the world are now connecting many hosts at a single location and it is not possible for every single device to have its own public IP address. To increase the number of addresses available, a new standard called IPv6 has been developed. Until IPv6 is finalized, other methods are needed to allow for the sharing of public addresses among more systems. The most effective solution is called network address translation (NAT), defined in the request for comments 1631 (RFC 1631).

NAT is a special type of router that has several different implementations. One popular method of implementation allows for the use of special, unroutable IP addresses on private or internal networks. The private addresses are translated to a public host address, which allows communication over the Internet. Three blocks of the unroutable, or private, IP addresses are defined in RFC 1597 and RFC 1918. The private...

Copyright Syngress Publishing, Inc. 2007 under license agreement with Books24x7

Products & Services
Domain Registration Services
Domain registration services register URLs as well as transferring and auctioning registered domains.
VPN Software
VPN software enables private communications over public computer networks and telecommunications infrastructure. Virtual private networks (VPN) provide network connectivity over long distances, and support network services such as file sharing and video conferencing.
Network Load Balancers
Network load balancers are components that distribute interactive traffic across a number of hosts using dynamically updated rules for load balancing, while providing a single system image to the client system.
VoIP Software
VoIP software is used to conduct telephone-like voice conversations across IP-based networks.
Network Routers
Network routers are protocol-dependent devices that connect subnetworks, or that break down a large network into smaller subnetworks.

Topics of Interest

Introduction We begin the process of securing the VoIP infrastructure by reviewing and validating the existing security infrastructure. Addition of VoIP components to a preexisting data network is...

Introduction This chapter will allow you to enable or disable Network Address Translation (NAT) for a single host, for a range of addresses, or for an entire network. There are two different ways to...

Introduction With the explosive growth of the Internet in the last decade, the number of available IP addresses has become scarce. To help ease the burden for unique IP addresses, three network...

2.6 Summary This chapter discussed the issues in designing an efficient addressing, naming, and configuration model for your network. Specifically, the following topics were covered: Each...

Introduction Another method to secure your internal network or DMZ network behind the firewall is to assign it a network or subnet from one of the reserved IP network numbers for private addressing.