Network Address Translation - NAT secrets they didn't teach you

  Рет қаралды 33,232

MikroTik

MikroTik

Күн бұрын

Network Address Translation (NAT) is something we use every day. Many people think they know how it works, but they don't. This time Druvis looks under the hood and all becomes clear - NAT explained!
0:00 Intro
0:18 NAT origins
1:26 The missing piece
3:43 Masquerade under the hood
5:57 Endpoint Independent Mapping
6:30 Secret Masquerade
7:06 Grand Summary
8:50 Outro

Пікірлер: 132
@stephanszarafinski9001
@stephanszarafinski9001 7 ай бұрын
Great video! I like it that you explain not only the basic things, but also more in depth stuff. That way the video is interesting for both beginners and more advanced users. Good visuals too!
@matelotjim9035
@matelotjim9035 7 ай бұрын
Another great video Druvis, explaining the bits that others miss.
@maxvideodrome4215
@maxvideodrome4215 7 ай бұрын
Nice work again Mikrotik - really enjoy your products.
@philippeastier7657
@philippeastier7657 7 ай бұрын
Thank you again, those series of videos are just great.
@user-zb2qm7gn7w
@user-zb2qm7gn7w 7 ай бұрын
Still missing ipv6 videos.
@DeFi-Macrodosing
@DeFi-Macrodosing 7 ай бұрын
You guys are great, and your devices too. I'd never heard of you before, until I got my ATL LTE router. Amazing. I'd love to know more about customising the router's firewall.
@vladislavkaras491
@vladislavkaras491 6 ай бұрын
I don't know if there is anything interesting and/or complicated in bridging adapters together, but if there is, would be interesting to watch it! Thanks for such great video!
@bartomiejsikora910
@bartomiejsikora910 7 ай бұрын
Hi MikroTik Guys. We need more videos like this. Thanks .
@kolifx
@kolifx 7 ай бұрын
Great video, concise and clear. Great follow up would be to explain how Zerotier can help if one (or both) networks is/are behind CG NAT.
@leratoradebe6438
@leratoradebe6438 7 ай бұрын
Great video, certainly learnt something!
@CarmineIannace
@CarmineIannace 7 ай бұрын
Excellent video! Paldies!
@LuisAriasSanchez
@LuisAriasSanchez Ай бұрын
Un material excelente. Muchas gracias.
@FranciscoMatusCL
@FranciscoMatusCL 5 ай бұрын
amazing content, thanks for your effort!
@mikrotik
@mikrotik 5 ай бұрын
Glad you enjoy it!
@vitea1
@vitea1 7 ай бұрын
Good video. Will be great to see video about DS-lite and IPv6
@brucemoriarty
@brucemoriarty 7 ай бұрын
amazing video and very informative :D
@drumaddict89
@drumaddict89 7 ай бұрын
since MT is a routing/router company ... more videos on BGP. basics, case studies, best practices, v7 limitations and BGP in-depth with routerOS! BGP needs to get more love at mikrotik again. also MPLS/VPLS case studies or tutorials would be great in context of ROSv7 configurations
@chadtaylor1148
@chadtaylor1148 7 ай бұрын
I have a /24 of public IP it was breeze to set up on VULTR with ROS6 but 7 has been a no go I absolutely cannot get it to announce. So I would very much love to see some more examples of BGP in version seven.
@drumaddict89
@drumaddict89 7 ай бұрын
@@chadtaylor1148 not examples alone ... improvements and features which are there in v6 !!!
@erlonsilva3396
@erlonsilva3396 6 ай бұрын
Currently version 7 is behaving like other manufacturers. You must have your prefix in the FIB so that it can be announced. In fact, not only that, but you need to create an addres-list with it and also send it in the out (export) filter.
@salembaabbad8783
@salembaabbad8783 7 ай бұрын
Thank you sir I really enjoyed the video,I hope you made a videos for network topology examples 😊
@SiBex_ovh
@SiBex_ovh 7 ай бұрын
Nice Music, this is a next level of video's :). I remember when in past, we use a Public IP on all internal PC. Police in Poland use Dual PC (one PC with Internet, second PC internal network). Those time was awesome, so big wow effect was in every category in IT.
@mikrotik
@mikrotik 6 ай бұрын
Thanks for the cool story from the old times. We will try to make more good videos :)
@jesusmedina-oi7sl
@jesusmedina-oi7sl 7 ай бұрын
Great video, make another one explaining load balancing techniques.
@gcinini
@gcinini 7 ай бұрын
Great video. Also loved the VLAN series. If you guys could go deeper with the VLAN videos presenting specific scenarios to increase security in home LANs leveraging VLANS and multiple Wi-Fi networks or other similar scenarios that would be great! Keep up the great work.
@mikrotik
@mikrotik 7 ай бұрын
Noted
@SecOps-7
@SecOps-7 7 ай бұрын
Thanks for the great video. Would love to see a video on WiFi configuration best practices, especially Radio wave frequency best practices on Mikrotik devices. Wifi wave2 does not do great out the box without some configuration and trial and error first. 😊
@Micheph
@Micheph 7 ай бұрын
Saved me rereads. Do not forget to remind us who are just users why it is important to read Mikrotik block diagrams.
@ollisollis
@ollisollis 7 ай бұрын
Great Video, but reduce the volume of music. Please.
@stevenm45
@stevenm45 7 ай бұрын
Yes, broadcast sound engineer here! Please re-mix to drop the background music by 10dB or so. Other than that I just learnt some extra stuff about NAT, thank you MT!
@mikkio5371
@mikkio5371 7 ай бұрын
😂​😂
@krusher00
@krusher00 7 ай бұрын
And 9:20 🎉
@SavroRus
@SavroRus 7 ай бұрын
thank you for clear explanation 🙏
@user-ic2fo5rg2l
@user-ic2fo5rg2l 7 ай бұрын
Дуже дякую за такі гарні відео 😉😊
@anakinskywalker8624
@anakinskywalker8624 7 ай бұрын
Thank you for this video topic :)
@user-fs4cx2uk4r
@user-fs4cx2uk4r 7 ай бұрын
Great video!!
@agentbayabas
@agentbayabas 6 ай бұрын
can you create an details like that on how port forwarding works i want like that with visualization
@SoranEngineer
@SoranEngineer 7 ай бұрын
great video thank you so much for explain
@black_ierax
@black_ierax 7 ай бұрын
A video going into detail for LTE, cell locking, and carrier aggregation. In a water bottling facility in Mount Athos, I am facing issues with my mobile operator. The cell tower that is located above Daphne is around 300m from the 4g router, and has power saving features enabled on high frequency bands, causing the router to drop connection to the cell tower. The router then establishes connection at cell towers located in Ierisos that is located around 36 ΚΜ, or at Sarti that is around 25km away, and located on the left of the dish. I am using a RBLHGR&R11e-LTE and waiting for a LHG LTE18 kit to arrive soon.
@jiucaibox
@jiucaibox 7 ай бұрын
This video is so magnificent, I hope it can be translate to various languages.
@frankh.4420
@frankh.4420 7 ай бұрын
Thank you for that informative video. What about ipv6 fundamentials and subnetting?
@phil2768
@phil2768 7 ай бұрын
Thank you!
@renekuhl7934
@renekuhl7934 7 ай бұрын
Good Video.. Kepp it up Guys!
@mikkio5371
@mikkio5371 7 ай бұрын
Port address translation. The last two is what I don't know about ( harping & carrier ) . Druvis is back !! Being a while .
@chaseendicott
@chaseendicott 6 ай бұрын
I would like to see more info about how Endpoint Independent NAT can help in a carrier grade NAT situation for ISP's that want to help open things up for customers so things aren't double NAT'ed. Setup and the benefits being highlighted would be helpful!
@chechitogmail
@chechitogmail 7 ай бұрын
a clarification on NAT action=same and the option not-by-dst also, will be nice thank you, good video
@mnsi_darryl
@mnsi_darryl 7 ай бұрын
Solid intro on how NAT work, perhaps you can expand on NAT forwarding rules in RouterOS since you touched on the port knocking topic :)
@mikrotik
@mikrotik 7 ай бұрын
For sure, more videos on NAT are coming.
@happy_dev
@happy_dev 7 ай бұрын
uPNP part is missing in the summary as one of the options for how to make port forwarding. for the next video, I would show ipv6 with examples - we don't need nat but at the same time how don't open any home device into the internet, etc. another topic - wifi k/v/r - what every letter means and demos with facetime/voip calls during transitions between APs
@mikrotik
@mikrotik 7 ай бұрын
Not planning to do IPv6 videos at the time, but more wifi videos can be expected.
@happy_dev
@happy_dev 7 ай бұрын
@@mikrotik btw, any news about 160mhz and wifi 6e devices? And more 2.5gb/s ports, please!
@gregmc3957
@gregmc3957 7 ай бұрын
Good video. Can you do a video on MSTP where vlans or redundant links between devices occur.
@pmcmar
@pmcmar 7 ай бұрын
Cool video. Maybe you could add the OSI model layer's namely the transport layer.. but it could get confusing 😅
@mikkio5371
@mikkio5371 7 ай бұрын
Network trip was doing some great vidoe on firewall though too
@Grmreeper100
@Grmreeper100 7 ай бұрын
Thank you for the greate work
@pavelsmarhels8868
@pavelsmarhels8868 6 ай бұрын
It would be great to hear something about (diff/incr) config backup of bunch of mikrotiks. With products like rancid + git.
@jeytis72
@jeytis72 7 ай бұрын
I'd like to see more videos about routing tables, routing rules, and firewall mangle marking. Thanks
@kiranrajr
@kiranrajr 7 ай бұрын
Hi Team, The Video was amazing and very helpful for us. Can you make a video explaining CG NAT in MikroTik?
@mikrotik
@mikrotik 7 ай бұрын
For sure, probably after the holidays.
@kiranrajr
@kiranrajr 7 ай бұрын
@@mikrotik Thank You 🙏🏻
@tlturner3
@tlturner3 7 ай бұрын
Great video. It would be be to explain a common misconception to those new to routing and that confusing source NAT with static NAT and destination NAT dynamic NAT.
@mikrotik
@mikrotik 6 ай бұрын
Ok, we will do more RouterOS specific NAT videos!
@hristobarbolov5953
@hristobarbolov5953 7 ай бұрын
An idea for a video - IPv6 and how to configure it
@criticalmoorhen
@criticalmoorhen 7 ай бұрын
Video idea - CAKE and queue trees. There is also lack of documentation from your side on Cake, so I guess video would do it. Personally I expect you to show off how to setup up CAKE with proper parameters and set up queue tree, all for home/homelab users. I would like to see general recommendations on what kind of queues you might recommend, how to prioritize primary network and give "leftover" traffic to guest network or seedbox. Also - great video!
@criticalmoorhen
@criticalmoorhen 7 ай бұрын
Another idea - how to properly set up hairpin NAT. It's one of those tricky areas to set up correctly and no "right" answer in forums too. :)
@mikrotik
@mikrotik 7 ай бұрын
We have a video about that kzfaq.info/get/bejne/Z69ledyovpzToIU.htmlsi=YvZBr2ygOkkPilp0
@nday345
@nday345 7 ай бұрын
Thank you for the video! Tell us how SNAT works for protocols other than TCP and UDP, for example ICMP, GRE, IPIP, etc. How does a router keep track of connections when several hosts on the local network behind a NAT send ICMP requests to the same host on the Internet? How does he understand which host on the local network to return the ICMP reply to?
@mikrotik
@mikrotik 7 ай бұрын
Valid questions, there will be something short on ICMP and NAT.
@user-pn4qz7dg2l
@user-pn4qz7dg2l 6 ай бұрын
RouterOS Firewall Mangle is fantastic. Please create new videos about different usages of Mangles and firewall rules like blocking Ads, doubling internet speed by using two ISPs, or even connecting to a website using a specific VPN interface. I also need to know how to monitor and debug the routing rules, connections, interfaces, and packets. Thank you for the great videos.
@user-wy2ys7eo8j
@user-wy2ys7eo8j 7 ай бұрын
chateau 5G ax update 7.13 后,找不到wlan1 wlan2 怎么解决?
@tannoy
@tannoy 7 ай бұрын
Great video. Would be good to add how to set this up on RouterOs. Thanks.
@mikrotik
@mikrotik 6 ай бұрын
Will do!
@IgorThompsonMusic
@IgorThompsonMusic 14 күн бұрын
bold start!
@rusnyasosat
@rusnyasosat 7 ай бұрын
Nice
@chadtaylor1148
@chadtaylor1148 7 ай бұрын
I really enjoy the deeper videos where they deep dive into a topic, explain things, programming examples etc. Dont get me wrong I don't want the fun ones to go away but I would love a weekly series where we could expect to see a technical video every Tuesday or something like that.
@jfernandez76
@jfernandez76 6 ай бұрын
For a next topic, please, consider talking about cross-vlan mDNS.
@examen1996
@examen1996 7 ай бұрын
Always loved mikrotik but never had one, really looking at a rb5009 , a device that i already recomended to a friend who bought it and is extremely happy with it. One great video ideea would be a entry 10gb home network for home labs, mikrotik(switch, router) equipment only. While I love openwrt, i cant help but wishing the quality of mikrotik hardware for my network . Regards
@HarishSharmaDelhi
@HarishSharmaDelhi 7 ай бұрын
I am small hotel owner and I would love to see a video that will explain how hotspot and usermanager work on RouterOS 7
@nicolaperotto1933
@nicolaperotto1933 5 ай бұрын
The music is disturbing and confusing: some people here has to concentrare to understand what you say. The video is very well done, interesting and informative. Thanks
@dummydummydummy7568
@dummydummydummy7568 7 ай бұрын
Hello, Very interesting video but could you please make other videos that delve deeper into the types of nat he showed? Thank you
@mikrotik
@mikrotik 7 ай бұрын
Absolutely! There will be demonstrations in RouterOS.
@dummydummydummy7568
@dummydummydummy7568 7 ай бұрын
Thank you@@mikrotik
@MohammedBizzan
@MohammedBizzan 7 ай бұрын
Hey Mikrotik, will we get an Apple Silicion native winbox app?
@mikrotik
@mikrotik 7 ай бұрын
Eventually ;)
@cruronet
@cruronet 7 ай бұрын
Hello i have a issue i have a server on my house port xxxx but when i turn of the server i pop up the router UI.... how do i prevent that happening
@aligenawi
@aligenawi 7 ай бұрын
grate work , if you lower or remove the music during the talking it will make it easy to concentrate and follow up the topic .
@MartinEscudero
@MartinEscudero 7 ай бұрын
HEY! When will routers have harpin nat activated by default and a DDNS integrated client for no-ip or other providers? Thanks
@mikrotik
@mikrotik 7 ай бұрын
Only a small percentage of customers will use Hairpin NAT, so there is no need to do the extra configuration for everyone. DDNS is integrated and available for everyone, just enable it in the IP Cloud section.
@matejsojka6683
@matejsojka6683 7 ай бұрын
make another video and show how to configure those nats explained here on mikrotik routers.
@mikrotik
@mikrotik 7 ай бұрын
There will be videos on all of them. We have already covered port-forwarding and Hairpin NAT in the past, however.
@meddle999
@meddle999 7 ай бұрын
IPv6 security topics please
@yingpan6436
@yingpan6436 7 ай бұрын
hello miktorik, how to nat dstnat range port to range ip on mikrotik router ?
@mikrotik
@mikrotik 6 ай бұрын
We will cover dstnat in more detail :)
@userbanned4419
@userbanned4419 7 ай бұрын
ну на вас давно подписан, по этому нашел)
@MateusProvesi
@MateusProvesi 5 ай бұрын
Please talk about IPv6.
@emanuelcoc
@emanuelcoc 7 ай бұрын
Muito bom
@cruelyamagaming7096
@cruelyamagaming7096 6 ай бұрын
When 5G sim router launching in india..?
@ssimeonovbg
@ssimeonovbg 7 ай бұрын
More info about CGnat please
@mikrotik
@mikrotik 7 ай бұрын
Sure, after the holidays.
@apruszko
@apruszko 7 ай бұрын
Dear Dru, please create some video about iot mqtt with SSL and safe configuration (now: mqtt credentials in config are in plain text, reading this config, an intruder can break our mqtt broker, please see that certificates and keys are no stored in config, I mean "/export teres" does not show critical information). Thanks for previous video - those helps me buy many mikrotik hardwares 😊
@mikrotik
@mikrotik 7 ай бұрын
Like with other sensitive data on your router - the key is to use strong user passwords and not hand them out to anyone you don't trust.
@rihardsbimanis8390
@rihardsbimanis8390 7 ай бұрын
Why i cant port forward with BITE mobile network? Mikrotik LTE device shows private address, so maybe they are using NAT and blocking port 80?
@mikrotik
@mikrotik 7 ай бұрын
Mobile operators usually use CG NAT and other techniques, so for port-forwarding to work they would have to configure it at their end.
@user-km4tt4ok8t
@user-km4tt4ok8t 7 ай бұрын
Rihards, did you buy from BITE static public IP address?
@Graham_Rule
@Graham_Rule 7 ай бұрын
Great content. Terrible background 'music' made it difficult to concentrate on the words though.
@nelsonlim5189
@nelsonlim5189 27 күн бұрын
please do a CGNAT video please
@mikrotik
@mikrotik 27 күн бұрын
Will do.
@zanydaproduction
@zanydaproduction 6 ай бұрын
Спасибо. Если добавите русские субтитры будет вообще фантастически❤. Mikrotik 👍🤟
@zanydaproduction
@zanydaproduction 6 ай бұрын
Хотя если смотреть через Яндекс браузер с переводом нейросети на РУССКИЙ то воОбще Агонь. 😀
@user-vy4sf5fl3n
@user-vy4sf5fl3n 7 ай бұрын
make bgp video settings on v7 mikrotik
@mikrotik
@mikrotik 7 ай бұрын
In the plans already :)
@sebastiankutter3630
@sebastiankutter3630 6 ай бұрын
I have an idea for a video series: Let's create our own ISP with MikroTik, including CGNAT, PPPoE, and so on.
@mikrotik
@mikrotik 6 ай бұрын
Depends on the region in the world. PPPoE is not used around here. I guess common ISP setups in Latvia would not be possible in your region.
@sebastiankutter3630
@sebastiankutter3630 6 ай бұрын
@@mikrotik In Germany you usually login to your isp with pppoe
@mikrotik
@mikrotik 6 ай бұрын
It's very sad, I'm sorry
@sebastiankutter3630
@sebastiankutter3630 6 ай бұрын
@@mikrotik How does it work in Latvia?
@phcsmile
@phcsmile 7 ай бұрын
How to use Mikrotik NAT or another. Trick. To avoid starlink detect internet sharing and stop throttle and tarping connection - bandwidth
@next3138
@next3138 7 ай бұрын
pls fix a problem ipv6 dhcp bad server duid 6660, ignore it
@next3138
@next3138 7 ай бұрын
SUP-137795
@sabitzubairzayn6945
@sabitzubairzayn6945 6 ай бұрын
Make a proper video about CGNAT if possible.
@mikrotik
@mikrotik 6 ай бұрын
Will do!
@user-pz3tq1wj1z
@user-pz3tq1wj1z 5 ай бұрын
ros The download speed is so slow
@notDacian
@notDacian 7 ай бұрын
The background music is way to loud!
@davidz1264
@davidz1264 7 ай бұрын
What is NAT? It‘s EVIL 🙈
@QueeeeenZ
@QueeeeenZ 7 ай бұрын
You are pronouncing the word ”allow” wrongly. The emphasis is on the last syllable.
@userbanned4419
@userbanned4419 7 ай бұрын
основные вопросы: по видео всё понятно, лучше туториалы делайте как настраивать оборудование конечным клиентам, тк ваше оборудование с среднем сигменте для конечного пользователя.
@husseinadil6290
@husseinadil6290 7 ай бұрын
The music has ruined the benefit of this video. Please make the background music calm and volume it down as much as possible. We are here to gain knowledge from you. Music is our last concern.
@mikrotik
@mikrotik 7 ай бұрын
We will try to do better.
@wisperinternetinalambrico8590
@wisperinternetinalambrico8590 7 ай бұрын
el nat deberia desaparecer para eso está ipv6
@kiharamuchangi4228
@kiharamuchangi4228 3 ай бұрын
Bridging Video
BGP multihoming - Part 1
12:45
MikroTik
Рет қаралды 12 М.
Multiple uplinks using PCC, Load balancing
16:22
MikroTik
Рет қаралды 71 М.
KINDNESS ALWAYS COME BACK
00:59
dednahype
Рет қаралды 169 МЛН
Nastya and SeanDoesMagic
00:16
Nastya
Рет қаралды 19 МЛН
Clown takes blame for missing candy 🍬🤣 #shorts
00:49
Yoeslan
Рет қаралды 39 МЛН
MikroTips: How to firewall
21:56
MikroTik
Рет қаралды 142 М.
Network Address Translation - Computerphile
10:50
Computerphile
Рет қаралды 159 М.
How to Configure VLANs in Proxmox
15:47
House of Logic blog
Рет қаралды 6 М.
What is a Protocol? (Deepdive)
18:14
LiveOverflow
Рет қаралды 162 М.
Make your router run Scripts!
6:54
MikroTik
Рет қаралды 11 М.
Subnets vs VLANs
5:51
PowerCert Animated Videos
Рет қаралды 546 М.
NAT and Firewall Explained
9:24
IBM Technology
Рет қаралды 99 М.
Самые крутые школьные гаджеты
0:49
Красиво, но телефон жаль
0:32
Бесполезные Новости
Рет қаралды 1,5 МЛН
Todos os modelos de smartphone
0:20
Spider Slack
Рет қаралды 60 МЛН
Какой ноутбук взять для учёбы? #msi #rtx4090 #laptop #юмор #игровой #apple #shorts
0:18