0Pricing
Linux Networking & TCP/IP for Developers · Урок

Трансляция сетевых адресов (NAT)

Изучите различные типы NAT и его роль в сохранении IPv4-адресов и обеспечении сетевой безопасности

«Трансляция сетевых адресов (NAT)» — бесплатный урок Linux Networking & TCP/IP for Developers на CoddyKit. Это урок 3 из 4. Ты можешь прочитать весь урок бесплатно ниже — а потом практиковать его прямо в браузере с встроенным редактором кода и ИИ-репетитором 24/7. Это часть пути обучения Linux Networking & TCP/IP for Developers, и твой прогресс синхронизируется между веб-версией и приложением CoddyKit. Курс Linux Networking & TCP/IP for Developers содержит 4 уроков всего.

Части этого урока еще не переведены и отображаются на английском.

What is Network Address Translation?

Welcome to the lesson on Network Address Translation (NAT)! NAT is a crucial technique used in computer networking, especially with IPv4.

Think of NAT as a clever translator for network addresses. It allows devices on a private network to communicate with the internet using a single public IP address.

Why NAT is Essential for IPv4

The main reason NAT became so important is the limited supply of IPv4 addresses. There simply aren't enough unique public IPv4 addresses for every device in the world.

  • IPv4 Conservation: NAT helps conserve public IPv4 addresses by allowing many private devices to share one.
  • Network Isolation: It also adds a layer of security by hiding the internal network structure from the outside world.

Private vs. Public IP Addresses

To understand NAT, you need to know about private and public IP addresses:

  • Private IPs: Used within a local network (e.g., your home or office). They are not routable on the internet. Examples: 192.168.1.10, 10.0.0.5.
  • Public IPs: Unique, globally routable addresses used on the internet. Your home router gets one from your Internet Service Provider (ISP).

NAT bridges these two worlds.

How NAT Works: The Core Idea

Imagine your router as a post office. When a letter (data packet) leaves your house (private network) for the outside world (internet), the post office changes the return address to its own (public IP).

When a reply comes back, the post office knows which house (private IP) to send it to. This is the basic idea behind NAT: translating addresses at the network boundary.

Source NAT (SNAT): Outbound Traffic

Source NAT (SNAT) is used for outbound connections, meaning when devices inside your private network want to reach the internet.

When a packet leaves your private network, the router changes the packet's source IP address from a private one to the router's public IP address. This is often called IP Masquerading.

SNAT Example: Accessing the Web

Here's how SNAT works when your laptop browses a website:

  1. Your laptop (192.168.1.10) sends a request to a website.
  2. Your router intercepts it, changes the source IP to its public IP (e.g., 203.0.113.5), and sends it to the internet.
  3. The website replies to 203.0.113.5.
  4. Your router receives the reply and translates the destination IP back to 192.168.1.10, forwarding it to your laptop.

Destination NAT (DNAT): Inbound Traffic

Destination NAT (DNAT), also known as Port Forwarding, is used for inbound connections. It allows external devices to connect to specific services running on a private device.

When a packet arrives from the internet, the router changes the packet's destination IP address from its public IP to a specific private IP and port within the network.

DNAT Example: Hosting a Game Server

If you host a game server on your PC (192.168.1.100) and want friends to connect:

  1. Your friend connects to your router's public IP (e.g., 203.0.113.5) on a specific port (e.g., 25565).
  2. Your router has a DNAT rule: any traffic to 203.0.113.5:25565 should be forwarded to 192.168.1.100:25565.
  3. The router translates the destination and sends the packet to your game server.
  4. The server's replies are then SNAT'd back out to your friend.

PAT: Port Address Translation

Most home routers use a type of NAT called Port Address Translation (PAT), also known as NAPT or IP Masquerading.

PAT allows multiple devices on a private network to share a single public IP address simultaneously. It does this by using different source port numbers for each outgoing connection to keep track of which internal device gets which incoming reply.

NAT's Security and Limitations

While NAT is great for address conservation and offers a basic security layer by hiding internal IPs, it's not a firewall:

  • Security: Hides internal network topology, making direct attacks harder.
  • Limitations: Can complicate peer-to-peer applications and some VPNs, as it breaks end-to-end connectivity. IPv6 aims to solve address scarcity without NAT.

Quick Check: Understanding NAT

Which type of NAT is primarily used to allow multiple internal devices to share a single public IP address when accessing the internet, often by modifying port numbers?

Recap: NAT's Role in Networking

We've explored Network Address Translation (NAT) and its vital role in modern networking. You now understand:

  • Why NAT is crucial for conserving IPv4 addresses.
  • The difference between private and public IP addresses.
  • How Source NAT (SNAT) handles outbound traffic.
  • How Destination NAT (DNAT) enables inbound access (port forwarding).
  • The common use of Port Address Translation (PAT) to share a single public IP.

NAT is a fundamental concept that enables the internet as we know it today!

Часто задаваемые вопросы

Урок «Трансляция сетевых адресов (NAT)» бесплатный?

Да — полный текст урока «Трансляция сетевых адресов (NAT)» бесплатно доступен здесь в веб-версии. Чтобы практиковать его интерактивно (встроенный редактор кода и ИИ-репетитор 24/7) и разблокировать остальной курс Linux Networking & TCP/IP for Developers, подпишись на CoddyKit PRO. Курс Linux Networking & TCP/IP for Developers содержит 4 уроков всего.

Чему я научусь в уроке «Трансляция сетевых адресов (NAT)»?

Изучите различные типы NAT и его роль в сохранении IPv4-адресов и обеспечении сетевой безопасности Ты практикуешь Linux Networking & TCP/IP for Developers с помощью реального кода, который запускаешь прямо в браузере, и ИИ-репетитор 24/7 отвечает на твои вопросы во время урока.

Нужен ли мне опыт, чтобы начать Linux Networking & TCP/IP for Developers?

Предыдущий опыт не требуется. Linux Networking & TCP/IP for Developers на CoddyKit структурирован для всех уровней — от новичков до продвинутых, поэтому ты можешь начать отсюда или с самого начала и учиться в своем темпе. Это урок 3 из 4.

Сколько времени занимает урок «Трансляция сетевых адресов (NAT)»?

Большинство уроков CoddyKit занимают около 5–10 минут. Каждый из них компактный и интерактивный, поэтому ты постоянно делаешь прогресс и продолжаешь с того же места в веб-версии и приложении.

Можно ли писать и запускать код в этом уроке Linux Networking & TCP/IP for Developers?

Да. Каждый урок Linux Networking & TCP/IP for Developers включает встроенный редактор кода, поэтому ты пишешь и запускаешь реальный код прямо в браузере и получаешь моментальную обратную связь от AI — локальная установка не требуется.

Все уроки этого курса

  1. Адресация и понятия IPv6
  2. Расширенные протоколы маршрутизации (RIP/OSPF)
  3. Трансляция сетевых адресов (NAT)
  4. Подсети и CIDR: углублённое изучение
← Назад к Linux Networking & TCP/IP for Developers