CCNA2: NAT

Description

CCNAv6
Sam Thomas
Flashcards by Sam Thomas, updated more than 1 year ago
Sam Thomas
Created by Sam Thomas almost 6 years ago
6
0

Resource summary

Question Answer
What is the private address spaces? 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16
What is the two main purposes of NAT -Translate network IPv4 address -Conserve public IPv4 addresses
Where is NAT usually configured? At a border router for a stub network
What is an inide local address? source host address seen from inside the network
What is the inside global address? soure host address seen from outside the network
What is the outside global address destination host address seen from outside its network
What is the outside local address destination host address seen from inside its network
Define Static NAT -one-to-one mapping of local and global addresses -Configured manually
Define Dynamic NAT -Uses pool of public addresses -Assigns on first-come-first served basis -Requires enough addresses for total number of simultaneous user sessions
Define Port Address Translation -maps multiple private addresses to single or few public addresses -NAT overload -Validates incoming packets were requested -uses port number (for TCP/UDP) and other identifiers for other protocols -required PAT to support protocols
Advantages of NAT -Conserves legally registered addressing scehme -Increases flexibility of connections -Provides consistency for internal network schemes -Provides some networ security
Disadvantages of NAT -Peformance is degraded -End-to-end functionality is degraded -End-to-end IP traceability is lost -Tunneling is more complicated
When connecting to an ISP does NAT translate to public or private address? Can be both depending on setup
Give a situation where static NAT is particulary useful Web servers
What type of NAT does most home routers use? PAT
What does NAT use for the session identifier for ICMP echo request Query ID
Define the concept of Next Avaliable port If NAT already has a mapping using the same port number if an incoming translation - it will use the next avaliable number
Is it required NAT supports specific protocols if a Layer 4 segment is not present (TCP/UDP) Yes
How does NAT conerve the legally registered addressng scheme - what does this mean? Allowing the privization of intranets Means that private addresses can be used for internal networks but when these networks want to communicate externally only a very small amount of addresses are neccasary (PAT)
How does NAT increase the flexibility of connections to the public network -Multiple pools -Backup pools -Load balancing pools
Should NAT be used to provide security? No - a stateful firewall should
What protocol is specificly affected by the peformance degregation of NAT? VOiP
With NAT the first packet is always ________ switched Process (swiched)
Do some protocols rely on end-to-end addressing. Which? Yes. Usually affects security protocols - eg tunneling protocols such as IPSec, L2TP and PPTP
How does NAT affect troubleshooting? Makes it difficult to trace packets and determine cause of problems
How does NAT affect tunneling protocols? Modifies value in the header - causes integrity tests to fail
What are three commands used to verify NAT show ip nat translations show ip nat statistics debug ip nat
What is port forwarding? Act of forwarding a network port from one network node to another Packet sent to public IP address can be forwarded to private IP addresses
Where is port forwarding neccasary On border gateway routers which use PAT - as there is no mapping between port numbers and inside local address to forward top
Does IPv6 have NAT? Yes and No. It has a NAT which translates IPv6 to IPv4 but no IPv6 ULA to IPv6 global unicast
What is IPv6s form of private addresses? How are they used? Unique local address Allow IPv6 communications across a local site Cannot be translated to global unicast
Prefix of an IPv6 unique local address FC00::/7
What is NAT64 Translate IPv4 packets to IPv6 packets
Which is NAT-PT? IPv4 to IPv6 translation protocol that was depreated and has been replaced by NAT64
Show full summary Hide full summary

Similar

CCNA Security 210-260 IINS - Exam 3
Mike M
CCNA Security 210-260 IINS - Exam 1
Mike M
CCNA Security 210-260 IINS - Exam 2
Mike M
CCNA Part 1
Axiom42
CCNA Answers – CCNA Exam
Abdul Demir
CCNA Part 2
Axiom42
Hálózat 5
Cougar
CCNA Security Chapter 1 Exam
d94829 d94829
CCNA Security HW 3 & 4 (also exam review)
Anthony Schulmeister
Hálózat 10
Cougar
CCNA Security Chapter 4 Exam
d94829 d94829