What are public network, private network, intranet and extranet?

Good afternoon, my network worker friend.

Recently, many novice friends often ask, what are the concepts of public network, private network, internal network, and external network, and how to define them.

Regarding the IP address, there is indeed no clear distinction, and there is no need to be too literal.

Intranet and extranet are the result of a frame of reference selection.

After all, it is an external network for you, but it is actually someone else's internal network. Each has its own definition, and at most it can only be analyzed in detail for specific issues.

However, in general, it is still possible to distinguish.

The internal and external networks are relative to the firewall. Inside the firewall is called the internal network, and vice versa is the external network.

Therefore, to a certain extent, the external network is equivalent to the public network, and the internal network is equivalent to the private network.

Then how to divide it specifically, let’s discuss it further.

Today's article reading benefits: "Illustrated Network Series (Full Set of Books)"

picture

Some nouns and concepts in the online world are often obscure and difficult to understand. Then this set of illustration series is very suitable for you. It is rich in pictures and combines theory with pictures, which is very popular.

Friends who need it can private message me and send the password "illustration" to get this complete set of electronic resources of the book.

01 Public network = external network? Private network = intranet?

I just said a little bit earlier, so can I understand it in this way?

The meaning of these four nouns is very simple.

public network = public network

private network = private network

intranet = internal network

extranet = external network

Suppose now we use uppercase letters to indicate the network group, followed by brackets followed by numbers to represent its size and how many computers there are in the group.

C(567918467)-China Internet Group

W(407619781)-Global Network Group

A(57619)-Aliyun server group

H(3) - your home network group

Then this contains some relationships, W←→C[A,H].

We know that because the domestic network is actually restricted, it can be called the world's largest LAN, so domestic network groups can (scientifically) access foreign network groups, and Alibaba Cloud and your own computer belong to C.

Then if your computer is in C, W is called the external network for you , and the network you are on is called the internal network , and vice versa.

The LAN is also the same concept. If you are in the LAN, then the external network is called the external network.

So what is a public network ? As the name suggests, it is a network that everyone can access.

For example, both H and A can access their own upper layer, that is, C, so C is called the public network for A and H.

Is the public network = external network? It can be possible, but there are some situations that require specific analysis of specific issues.

For example, sometimes there is a self-built WAN in a large-scale network, that is, our self-built backbone network. We also call this kind of backbone network a public network.

Then the internal network is also called the intranet, this situation is not the same.

For example, like the government affairs extranet or the government affairs network, the public part of the government affairs network cannot actually access the Internet, but it is also called the public network .

Private network , private network, network that cannot be accessed without authorization.

The local area network is also a private network in a certain sense. The router only provides permission and connection to access the external network, so for A and H, they are also private networks for each other.

So in fact, there is no need to be too entangled in the name, this is not clearly defined.

02 "Intranet" LAN

Let's talk about it next.

An intranet is also called a local area network. In terms of scope, an intranet is a small part of the network.

A local area network refers to a computer group composed of multiple computers interconnected in a certain area. Usually within a radius of several kilometers.

Local area network can realize functions such as file management, application software sharing, printer sharing, scheduling within the working group, e-mail and fax communication services.

A local area network is closed and can consist of two computers in an office, or thousands of computers in a company.

picture

The intranet we often say is literally different from the extranet.

That is to say, the intranet is generally used for mutual communication between computers in the LAN. If you need to access the Internet, you need to use the external network.

Main features of LAN:

  • Covering a small geographical area, it is suitable for small-scale networking. Such as schools, factories, government agencies, etc.

  • Use a specially laid transmission medium for networking, and the data transmission rate is high (10Mb/s~10Gb/s);

  • Short communication delay time and high reliability;

  • LAN can support multiple transmission media;

03 "Extranet" WAN

The external network is the wide area network, and is generally called the public network.

It is a remote network that connects computers in LANs or MANs in different regions.

picture

It is a remote network that connects LAN or MAN computer communication in different regions.

It usually spans a large physical range, covering a range from tens of kilometers to thousands of kilometers. It can connect multiple regions, cities and countries, or span several continents and provide long-distance communication, forming an international network. remote network.

A WAN is not the same as the Internet.

04 "NAT" address translation technology

Here is a brief talk about NAT - "Network Address Translation" technology.

It is a technology that translates internal private network addresses (IP addresses) into legal network IP addresses.

It roughly means that NAT is to use internal addresses in the LAN, and when the internal nodes want to communicate with the external network, the internal addresses are replaced with public addresses at the gateway, so that they can be used normally on the external public network (internet).

picture

NAT can enable multiple computers to share Internet connections, and this function solves the problem of shortage of public IP addresses.

Through this method, you can only apply for a legal IP address, and connect the computers in the entire LAN to the Internet.

It is precisely because of the emergence of NAT technology that the intranet address can easily access the Internet.

05 The difference between intranet and extranet, 2 examples to explain clearly

picture

As shown in the figure, suppose our computer is device one and wants to visit Baidu.

01   How to use the campus network 

If you use the campus network, you first need to convert our internal network ip to the external network ip of the campus network through the router of the campus network.

Then connect to Hunan Telecom's gateway through this external network ip, and finally connect to Baidu's gateway.

Baidu returns the information you requested to your campus network gateway, and the campus network gateway then transmits the information to you (the entire network has a mesh structure.

It will automatically find a path to Baidu - based on depth-first search or breadth-first search).

This process is similar to Taobao shopping, just change it.

Suppose you ordered a book at school, and Taobao will start shipping it to you when it receives your order and prepares the items.

He found that your delivery address is in Hunan, so it may depart from Hangzhou, go to the transit station in Fujian first, and then to the transit station in Jiangxi.

Suddenly found that the transfer station from Jiangxi to Hunan was blocked, so it had to go around to the transfer station in Guangdong, and finally to the transfer station in Hunan.

These transit stations are equivalent to various gateways on the public network.

When you arrive at the Hunan transfer station, the courier brother will deliver the package to your school gate (this is the last level of gateway).

At this time, the courier brother left, and the management staff at the school gate took the package to you according to your dormitory information. (Information exchange within the LAN is handled by the gateway of the campus network)

This is a bit difficult for people who are new to the Internet to understand the difference between intranet ip and public ip, so let's give another example.

02   One internal, one external 

We compare room 201 of the hotel to the intranet ip, so any hotel may have room 201. If you are hungry, you will tell the waiter: "I am in room 201, please send some food over."

And if you want to order takeaway, you just tell the store to send it to room 201 (intranet ip), and it is impossible for outsiders to know.

At this time, you have to tell the store to find you in a certain hotel (public network ip) plus room 201 in a certain district of a certain city.

The public network ip address assigned by the operator (a certain hotel in a certain district of a certain city) is also the hotel where you live, and room 201 (intranet ip) is allocated by the hotel housekeeper (router).

So a hotel can have many rooms (intranet ip) but when a friend outside asks where you live, you will definitely not say that you live in room 201 (intranet ip) but that you live in a certain district of a certain city A certain hotel (public network ip).

This is the essential difference between internal network ip and public network ip.

One for internal and one for external.

03 5 points you need to know 

Say a few points of attention:

1. The public network ip is unique worldwide, while the internal network ip is unique only within the LAN

2. The intranet IPs of all computers in a local area network are different from each other, but share one external network IP.

Just like the previous hotel example:

The name of your school is only one in the whole world, but the classroom No. 3 on the 3rd floor of Building A in your school is unique only within your campus.

Other schools also have Classroom 3 on the 3rd floor of Building A.

You can only tell the courier brother, please help me deliver the package to xx University, but you cannot say please help me deliver the package to Room 3, Floor 3, Building A.

3. In the LAN, each computer can assign its own IP, but this IP is only valid in the LAN.

And if you connect your computer to the Internet, your network provider's server will assign you an IP address, which is your IP on the external network.

Two IPs exist at the same time, one internal and one external.

4. The IP addresses on the Internet (that is, the external network IP) are uniformly managed by an organization called "IANA (Internet Network Assignment Authority)".

Due to the unreasonable allocation and the limitations of the IPv4 protocol itself, the IP address resources of the Internet are becoming more and more tense.

IANA reserves part of class A, B, and C IP addresses for local area network use.

The details are as follows - IP address space:

Class a network 10.0.0.0 ~ 10.255.255.255

Class b network 172.16.0.0 ~ 172.31.255.255

Class c network 192.168.0.0~ 192.168.255.255

In other words, if the ip address you find is within the range of the above-mentioned A, B, and C IP addresses, it must be the ip address of the local area network, otherwise it is the address of the public network.

5. In real life, there are not only the first-level NET technology, but also the second-level NET technology.

That is to say, your campus gateway is also just a LAN. More addresses can be obtained through multi-level conversion.

rule of thumb -

1. The general telecom ADSL bandwidth is a (dynamic) public network IP before the large bandwidth is upgraded. If you spend a little money to upgrade to 100M fiber optic Internet access, 99.99% are intranet IPs, and 0.01% are cases that I have not found.

2. 99.99% of the agent network operators are intranet IPs, such as Great Wall Bandwidth, Juyou Ejia, etc.

3. 99.99% of fiber optic Internet access is intranet IP.

Intuitive method -

The addresses of the following IP segments are all intranet IP addresses

10.0.0.0 to 10.255.255.255

172.16.0.0 to 172.31.255.255

192.168.0.0 to 192.168.255.255

Finishing: Lao Yang 丨 10-year senior network engineer, more network workers to improve dry goods, please pay attention to the official account: Network Engineer Club

Guess you like

Origin blog.csdn.net/SPOTO2021/article/details/132337787