Network Address Translation - NAT secrets they didn't teach you

  Рет қаралды 31,739

MikroTik

MikroTik

Күн бұрын

Network Address Translation (NAT) is something we use every day. Many people think they know how it works, but they don't. This time Druvis looks under the hood and all becomes clear - NAT explained!
0:00 Intro
0:18 NAT origins
1:26 The missing piece
3:43 Masquerade under the hood
5:57 Endpoint Independent Mapping
6:30 Secret Masquerade
7:06 Grand Summary
8:50 Outro

Пікірлер: 131
@ollisollis
@ollisollis 6 ай бұрын
Great Video, but reduce the volume of music. Please.
@stevenm45
@stevenm45 6 ай бұрын
Yes, broadcast sound engineer here! Please re-mix to drop the background music by 10dB or so. Other than that I just learnt some extra stuff about NAT, thank you MT!
@mikkio5371
@mikkio5371 6 ай бұрын
😂​😂
@krusher00
@krusher00 6 ай бұрын
And 9:20 🎉
@stephanszarafinski9001
@stephanszarafinski9001 6 ай бұрын
Great video! I like it that you explain not only the basic things, but also more in depth stuff. That way the video is interesting for both beginners and more advanced users. Good visuals too!
@matelotjim9035
@matelotjim9035 6 ай бұрын
Another great video Druvis, explaining the bits that others miss.
@user-zb2qm7gn7w
@user-zb2qm7gn7w 6 ай бұрын
Still missing ipv6 videos.
@bartomiejsikora910
@bartomiejsikora910 6 ай бұрын
Hi MikroTik Guys. We need more videos like this. Thanks .
@maxvideodrome4215
@maxvideodrome4215 6 ай бұрын
Nice work again Mikrotik - really enjoy your products.
@philippeastier7657
@philippeastier7657 6 ай бұрын
Thank you again, those series of videos are just great.
@vladislavkaras491
@vladislavkaras491 6 ай бұрын
I don't know if there is anything interesting and/or complicated in bridging adapters together, but if there is, would be interesting to watch it! Thanks for such great video!
@DeFi-Macrodosing
@DeFi-Macrodosing 6 ай бұрын
You guys are great, and your devices too. I'd never heard of you before, until I got my ATL LTE router. Amazing. I'd love to know more about customising the router's firewall.
@kolifx
@kolifx 6 ай бұрын
Great video, concise and clear. Great follow up would be to explain how Zerotier can help if one (or both) networks is/are behind CG NAT.
@drumaddict89
@drumaddict89 6 ай бұрын
since MT is a routing/router company ... more videos on BGP. basics, case studies, best practices, v7 limitations and BGP in-depth with routerOS! BGP needs to get more love at mikrotik again. also MPLS/VPLS case studies or tutorials would be great in context of ROSv7 configurations
@chadtaylor1148
@chadtaylor1148 6 ай бұрын
I have a /24 of public IP it was breeze to set up on VULTR with ROS6 but 7 has been a no go I absolutely cannot get it to announce. So I would very much love to see some more examples of BGP in version seven.
@drumaddict89
@drumaddict89 6 ай бұрын
@@chadtaylor1148 not examples alone ... improvements and features which are there in v6 !!!
@erlonsilva3396
@erlonsilva3396 5 ай бұрын
Currently version 7 is behaving like other manufacturers. You must have your prefix in the FIB so that it can be announced. In fact, not only that, but you need to create an addres-list with it and also send it in the out (export) filter.
@LuisAriasSanchez
@LuisAriasSanchez 29 күн бұрын
Un material excelente. Muchas gracias.
@gcinini
@gcinini 6 ай бұрын
Great video. Also loved the VLAN series. If you guys could go deeper with the VLAN videos presenting specific scenarios to increase security in home LANs leveraging VLANS and multiple Wi-Fi networks or other similar scenarios that would be great! Keep up the great work.
@mikrotik
@mikrotik 6 ай бұрын
Noted
@FranciscoMatusCL
@FranciscoMatusCL 5 ай бұрын
amazing content, thanks for your effort!
@mikrotik
@mikrotik 5 ай бұрын
Glad you enjoy it!
@leratoradebe6438
@leratoradebe6438 6 ай бұрын
Great video, certainly learnt something!
@SiBex_ovh
@SiBex_ovh 6 ай бұрын
Nice Music, this is a next level of video's :). I remember when in past, we use a Public IP on all internal PC. Police in Poland use Dual PC (one PC with Internet, second PC internal network). Those time was awesome, so big wow effect was in every category in IT.
@mikrotik
@mikrotik 6 ай бұрын
Thanks for the cool story from the old times. We will try to make more good videos :)
@Micheph
@Micheph 6 ай бұрын
Saved me rereads. Do not forget to remind us who are just users why it is important to read Mikrotik block diagrams.
@vitea1
@vitea1 6 ай бұрын
Good video. Will be great to see video about DS-lite and IPv6
@CarmineIannace
@CarmineIannace 6 ай бұрын
Excellent video! Paldies!
@brucemoriarty
@brucemoriarty 6 ай бұрын
amazing video and very informative :D
@jesusmedina-oi7sl
@jesusmedina-oi7sl 6 ай бұрын
Great video, make another one explaining load balancing techniques.
@SecOps-7
@SecOps-7 6 ай бұрын
Thanks for the great video. Would love to see a video on WiFi configuration best practices, especially Radio wave frequency best practices on Mikrotik devices. Wifi wave2 does not do great out the box without some configuration and trial and error first. 😊
@black_ierax
@black_ierax 6 ай бұрын
A video going into detail for LTE, cell locking, and carrier aggregation. In a water bottling facility in Mount Athos, I am facing issues with my mobile operator. The cell tower that is located above Daphne is around 300m from the 4g router, and has power saving features enabled on high frequency bands, causing the router to drop connection to the cell tower. The router then establishes connection at cell towers located in Ierisos that is located around 36 ΚΜ, or at Sarti that is around 25km away, and located on the left of the dish. I am using a RBLHGR&R11e-LTE and waiting for a LHG LTE18 kit to arrive soon.
@SavroRus
@SavroRus 6 ай бұрын
thank you for clear explanation 🙏
@user-fs4cx2uk4r
@user-fs4cx2uk4r 6 ай бұрын
Great video!!
@salembaabbad8783
@salembaabbad8783 6 ай бұрын
Thank you sir I really enjoyed the video,I hope you made a videos for network topology examples 😊
@agentbayabas
@agentbayabas 5 ай бұрын
can you create an details like that on how port forwarding works i want like that with visualization
@anakinskywalker8624
@anakinskywalker8624 6 ай бұрын
Thank you for this video topic :)
@happy_dev
@happy_dev 6 ай бұрын
uPNP part is missing in the summary as one of the options for how to make port forwarding. for the next video, I would show ipv6 with examples - we don't need nat but at the same time how don't open any home device into the internet, etc. another topic - wifi k/v/r - what every letter means and demos with facetime/voip calls during transitions between APs
@mikrotik
@mikrotik 6 ай бұрын
Not planning to do IPv6 videos at the time, but more wifi videos can be expected.
@happy_dev
@happy_dev 6 ай бұрын
@@mikrotik btw, any news about 160mhz and wifi 6e devices? And more 2.5gb/s ports, please!
@user-ic2fo5rg2l
@user-ic2fo5rg2l 6 ай бұрын
Дуже дякую за такі гарні відео 😉😊
@mnsi_darryl
@mnsi_darryl 6 ай бұрын
Solid intro on how NAT work, perhaps you can expand on NAT forwarding rules in RouterOS since you touched on the port knocking topic :)
@mikrotik
@mikrotik 6 ай бұрын
For sure, more videos on NAT are coming.
@phil2768
@phil2768 6 ай бұрын
Thank you!
@chaseendicott
@chaseendicott 6 ай бұрын
I would like to see more info about how Endpoint Independent NAT can help in a carrier grade NAT situation for ISP's that want to help open things up for customers so things aren't double NAT'ed. Setup and the benefits being highlighted would be helpful!
@SoranEngineer
@SoranEngineer 6 ай бұрын
great video thank you so much for explain
@renekuhl7934
@renekuhl7934 6 ай бұрын
Good Video.. Kepp it up Guys!
@jiucaibox
@jiucaibox 6 ай бұрын
This video is so magnificent, I hope it can be translate to various languages.
@mikkio5371
@mikkio5371 6 ай бұрын
Port address translation. The last two is what I don't know about ( harping & carrier ) . Druvis is back !! Being a while .
@chechitogmail
@chechitogmail 6 ай бұрын
a clarification on NAT action=same and the option not-by-dst also, will be nice thank you, good video
@mikkio5371
@mikkio5371 6 ай бұрын
Network trip was doing some great vidoe on firewall though too
@chadtaylor1148
@chadtaylor1148 6 ай бұрын
I really enjoy the deeper videos where they deep dive into a topic, explain things, programming examples etc. Dont get me wrong I don't want the fun ones to go away but I would love a weekly series where we could expect to see a technical video every Tuesday or something like that.
@Grmreeper100
@Grmreeper100 6 ай бұрын
Thank you for the greate work
@nicolaperotto1933
@nicolaperotto1933 5 ай бұрын
The music is disturbing and confusing: some people here has to concentrare to understand what you say. The video is very well done, interesting and informative. Thanks
@criticalmoorhen
@criticalmoorhen 6 ай бұрын
Video idea - CAKE and queue trees. There is also lack of documentation from your side on Cake, so I guess video would do it. Personally I expect you to show off how to setup up CAKE with proper parameters and set up queue tree, all for home/homelab users. I would like to see general recommendations on what kind of queues you might recommend, how to prioritize primary network and give "leftover" traffic to guest network or seedbox. Also - great video!
@criticalmoorhen
@criticalmoorhen 6 ай бұрын
Another idea - how to properly set up hairpin NAT. It's one of those tricky areas to set up correctly and no "right" answer in forums too. :)
@mikrotik
@mikrotik 6 ай бұрын
We have a video about that kzbin.info/www/bejne/Z3qYd6ytjpuiprMsi=YvZBr2ygOkkPilp0
@frankh.4420
@frankh.4420 6 ай бұрын
Thank you for that informative video. What about ipv6 fundamentials and subnetting?
@jeytis72
@jeytis72 6 ай бұрын
I'd like to see more videos about routing tables, routing rules, and firewall mangle marking. Thanks
@kiranrajr
@kiranrajr 6 ай бұрын
Hi Team, The Video was amazing and very helpful for us. Can you make a video explaining CG NAT in MikroTik?
@mikrotik
@mikrotik 6 ай бұрын
For sure, probably after the holidays.
@kiranrajr
@kiranrajr 6 ай бұрын
@@mikrotik Thank You 🙏🏻
@pavelsmarhels8868
@pavelsmarhels8868 6 ай бұрын
It would be great to hear something about (diff/incr) config backup of bunch of mikrotiks. With products like rancid + git.
@pmcmar
@pmcmar 6 ай бұрын
Cool video. Maybe you could add the OSI model layer's namely the transport layer.. but it could get confusing 😅
@user-pn4qz7dg2l
@user-pn4qz7dg2l 6 ай бұрын
RouterOS Firewall Mangle is fantastic. Please create new videos about different usages of Mangles and firewall rules like blocking Ads, doubling internet speed by using two ISPs, or even connecting to a website using a specific VPN interface. I also need to know how to monitor and debug the routing rules, connections, interfaces, and packets. Thank you for the great videos.
@tlturner3
@tlturner3 6 ай бұрын
Great video. It would be be to explain a common misconception to those new to routing and that confusing source NAT with static NAT and destination NAT dynamic NAT.
@mikrotik
@mikrotik 6 ай бұрын
Ok, we will do more RouterOS specific NAT videos!
@gregmc3957
@gregmc3957 6 ай бұрын
Good video. Can you do a video on MSTP where vlans or redundant links between devices occur.
@rusnyasosat
@rusnyasosat 6 ай бұрын
Nice
@aligenawi
@aligenawi 6 ай бұрын
grate work , if you lower or remove the music during the talking it will make it easy to concentrate and follow up the topic .
@examen1996
@examen1996 6 ай бұрын
Always loved mikrotik but never had one, really looking at a rb5009 , a device that i already recomended to a friend who bought it and is extremely happy with it. One great video ideea would be a entry 10gb home network for home labs, mikrotik(switch, router) equipment only. While I love openwrt, i cant help but wishing the quality of mikrotik hardware for my network . Regards
@hristobarbolov5953
@hristobarbolov5953 6 ай бұрын
An idea for a video - IPv6 and how to configure it
@jfernandez76
@jfernandez76 6 ай бұрын
For a next topic, please, consider talking about cross-vlan mDNS.
@nday345
@nday345 6 ай бұрын
Thank you for the video! Tell us how SNAT works for protocols other than TCP and UDP, for example ICMP, GRE, IPIP, etc. How does a router keep track of connections when several hosts on the local network behind a NAT send ICMP requests to the same host on the Internet? How does he understand which host on the local network to return the ICMP reply to?
@mikrotik
@mikrotik 6 ай бұрын
Valid questions, there will be something short on ICMP and NAT.
@MohammedBizzan
@MohammedBizzan 6 ай бұрын
Hey Mikrotik, will we get an Apple Silicion native winbox app?
@mikrotik
@mikrotik 6 ай бұрын
Eventually ;)
@cruronet
@cruronet 6 ай бұрын
Hello i have a issue i have a server on my house port xxxx but when i turn of the server i pop up the router UI.... how do i prevent that happening
@HarishSharmaDelhi
@HarishSharmaDelhi 6 ай бұрын
I am small hotel owner and I would love to see a video that will explain how hotspot and usermanager work on RouterOS 7
@tannoy
@tannoy 6 ай бұрын
Great video. Would be good to add how to set this up on RouterOs. Thanks.
@mikrotik
@mikrotik 6 ай бұрын
Will do!
@user-wy2ys7eo8j
@user-wy2ys7eo8j 6 ай бұрын
chateau 5G ax update 7.13 后,找不到wlan1 wlan2 怎么解决?
@dummydummydummy7568
@dummydummydummy7568 6 ай бұрын
Hello, Very interesting video but could you please make other videos that delve deeper into the types of nat he showed? Thank you
@mikrotik
@mikrotik 6 ай бұрын
Absolutely! There will be demonstrations in RouterOS.
@dummydummydummy7568
@dummydummydummy7568 6 ай бұрын
Thank you@@mikrotik
@userbanned4419
@userbanned4419 6 ай бұрын
ну на вас давно подписан, по этому нашел)
@MartinEscudero
@MartinEscudero 6 ай бұрын
HEY! When will routers have harpin nat activated by default and a DDNS integrated client for no-ip or other providers? Thanks
@mikrotik
@mikrotik 6 ай бұрын
Only a small percentage of customers will use Hairpin NAT, so there is no need to do the extra configuration for everyone. DDNS is integrated and available for everyone, just enable it in the IP Cloud section.
@matejsojka6683
@matejsojka6683 6 ай бұрын
make another video and show how to configure those nats explained here on mikrotik routers.
@mikrotik
@mikrotik 6 ай бұрын
There will be videos on all of them. We have already covered port-forwarding and Hairpin NAT in the past, however.
@zanydaproduction
@zanydaproduction 6 ай бұрын
Спасибо. Если добавите русские субтитры будет вообще фантастически❤. Mikrotik 👍🤟
@zanydaproduction
@zanydaproduction 5 ай бұрын
Хотя если смотреть через Яндекс браузер с переводом нейросети на РУССКИЙ то воОбще Агонь. 😀
@Graham_Rule
@Graham_Rule 6 ай бұрын
Great content. Terrible background 'music' made it difficult to concentrate on the words though.
@apruszko
@apruszko 6 ай бұрын
Dear Dru, please create some video about iot mqtt with SSL and safe configuration (now: mqtt credentials in config are in plain text, reading this config, an intruder can break our mqtt broker, please see that certificates and keys are no stored in config, I mean "/export teres" does not show critical information). Thanks for previous video - those helps me buy many mikrotik hardwares 😊
@mikrotik
@mikrotik 6 ай бұрын
Like with other sensitive data on your router - the key is to use strong user passwords and not hand them out to anyone you don't trust.
@meddle999
@meddle999 6 ай бұрын
IPv6 security topics please
@emanuelcoc
@emanuelcoc 6 ай бұрын
Muito bom
@MateusProvesi
@MateusProvesi 5 ай бұрын
Please talk about IPv6.
@phcsmile
@phcsmile 6 ай бұрын
How to use Mikrotik NAT or another. Trick. To avoid starlink detect internet sharing and stop throttle and tarping connection - bandwidth
@cruelyamagaming7096
@cruelyamagaming7096 6 ай бұрын
When 5G sim router launching in india..?
@yingpan6436
@yingpan6436 6 ай бұрын
hello miktorik, how to nat dstnat range port to range ip on mikrotik router ?
@mikrotik
@mikrotik 6 ай бұрын
We will cover dstnat in more detail :)
@rihardsbimanis8390
@rihardsbimanis8390 6 ай бұрын
Why i cant port forward with BITE mobile network? Mikrotik LTE device shows private address, so maybe they are using NAT and blocking port 80?
@mikrotik
@mikrotik 6 ай бұрын
Mobile operators usually use CG NAT and other techniques, so for port-forwarding to work they would have to configure it at their end.
@user-km4tt4ok8t
@user-km4tt4ok8t 6 ай бұрын
Rihards, did you buy from BITE static public IP address?
@ssimeonovbg
@ssimeonovbg 6 ай бұрын
More info about CGnat please
@mikrotik
@mikrotik 6 ай бұрын
Sure, after the holidays.
@sebastiankutter3630
@sebastiankutter3630 5 ай бұрын
I have an idea for a video series: Let's create our own ISP with MikroTik, including CGNAT, PPPoE, and so on.
@mikrotik
@mikrotik 5 ай бұрын
Depends on the region in the world. PPPoE is not used around here. I guess common ISP setups in Latvia would not be possible in your region.
@sebastiankutter3630
@sebastiankutter3630 5 ай бұрын
@@mikrotik In Germany you usually login to your isp with pppoe
@mikrotik
@mikrotik 5 ай бұрын
It's very sad, I'm sorry
@sebastiankutter3630
@sebastiankutter3630 5 ай бұрын
@@mikrotik How does it work in Latvia?
@nelsonlim5189
@nelsonlim5189 9 күн бұрын
please do a CGNAT video please
@mikrotik
@mikrotik 9 күн бұрын
Will do.
@user-vy4sf5fl3n
@user-vy4sf5fl3n 6 ай бұрын
make bgp video settings on v7 mikrotik
@mikrotik
@mikrotik 6 ай бұрын
In the plans already :)
@next3138
@next3138 6 ай бұрын
pls fix a problem ipv6 dhcp bad server duid 6660, ignore it
@next3138
@next3138 6 ай бұрын
SUP-137795
@sabitzubairzayn6945
@sabitzubairzayn6945 6 ай бұрын
Make a proper video about CGNAT if possible.
@mikrotik
@mikrotik 6 ай бұрын
Will do!
@user-pz3tq1wj1z
@user-pz3tq1wj1z 5 ай бұрын
ros The download speed is so slow
@notDacian
@notDacian 6 ай бұрын
The background music is way to loud!
@userbanned4419
@userbanned4419 6 ай бұрын
основные вопросы: по видео всё понятно, лучше туториалы делайте как настраивать оборудование конечным клиентам, тк ваше оборудование с среднем сигменте для конечного пользователя.
@QueeeeenZ
@QueeeeenZ 6 ай бұрын
You are pronouncing the word ”allow” wrongly. The emphasis is on the last syllable.
@husseinadil6290
@husseinadil6290 6 ай бұрын
The music has ruined the benefit of this video. Please make the background music calm and volume it down as much as possible. We are here to gain knowledge from you. Music is our last concern.
@mikrotik
@mikrotik 6 ай бұрын
We will try to do better.
@davidz1264
@davidz1264 6 ай бұрын
What is NAT? It‘s EVIL 🙈
@wisperinternetinalambrico8590
@wisperinternetinalambrico8590 6 ай бұрын
el nat deberia desaparecer para eso está ipv6
@kiharamuchangi4228
@kiharamuchangi4228 2 ай бұрын
Bridging Video
BGP multihoming - Part 1
12:45
MikroTik
Рет қаралды 12 М.
Вечный ДВИГАТЕЛЬ!⚙️ #shorts
00:27
Гараж 54
Рет қаралды 14 МЛН
Always be more smart #shorts
00:32
Jin and Hattie
Рет қаралды 46 МЛН
Я нашел кто меня пранкует!
00:51
Аришнев
Рет қаралды 3,8 МЛН
5 reasons EVERYONE needs a home server
12:05
TechHut
Рет қаралды 307 М.
Network Address Translation - Computerphile
10:50
Computerphile
Рет қаралды 158 М.
I Wrote HTTP "From Scratch" (It Was Easy)
19:07
Sean Bix
Рет қаралды 12 М.
Make your router run Scripts!
6:54
MikroTik
Рет қаралды 10 М.
Port knocking with MikroTik
11:36
MikroTik
Рет қаралды 16 М.
Why Pi-hole when you can RouterOS adlist?
4:42
MikroTik
Рет қаралды 9 М.
NAT - SNAT, DNAT, PAT & Port Forwarding
9:50
Sunny Classroom
Рет қаралды 349 М.
MikroTips: How to firewall
21:56
MikroTik
Рет қаралды 141 М.
Что еще за съемные фронталки от Vivo? #vivo
0:41
Clicks чехол-клавиатура для iPhone ⌨️
0:59