[Common sense of network planning] Public network access to intranet: Intranet penetration


Record the recently encountered intranet penetration technology.

Exclusive bandwidth, teach you to build your own intranet penetration server (based on frp and zerotier moon server)

【Hardcore】Public network access? Intranet penetration! Get started with zero experience!

IP address

By setting an address for each device, the location of the device can be located. Through this address, devices can send videos to each other and so on.

The commonly used IP address nowadays is version 4, ie IPv4.

insert image description here

IPv4 is composed of 32-bit binary numbers. For the convenience of memory, it is usually divided into 4 parts, and each part is 0-255. There are 4.228 billion addresses in permutation and combination.

insert image description here

Solve the problem that IPv4 addresses are not enough

For NAS users, how to access storage devices at home (such as installing monitoring equipment at home) is a problem that most people will encounter. Today, when IPv4 resources are severely scarce, most users have been unable to obtain independent IPv4 addresses (IPv4 public network IP) 没有公网IP就失去了通过端口映射来访问内网设备的一个可能性.

NAT address translation technology

Based on IPv4 upgrade, consider compatibility.

insert image description here

Home routers are assigned 公网IPaddresses, and mobile computers are assigned addresses by routers 内网(私有/局域网)IP.

insert image description here

The following 4 network segments are allocated for intranet IP use:

insert image description here
insert image description here

This process has a disadvantage, that is, you cannot directly access the intranet from the public network, and must be forwarded by a router.

A solution: intranet penetration

A tunnel is directly established between the transit server and the intranet device.

insert image description here

Many brands of NAS generally provide transit services for intranet penetration. However, for most brands, the investment in intranet penetration services is only at the level of allowing users to perform basic operations, and they may not be able to connect when they are busy. We can also 自建的服务器achieve access to intranet devices (due to the stable self-built server performance is more controllable, 最稳定的内网穿透方式之一).

The common free FRPand paid ones 向日葵are all in this mode.
ZerotierThe principle is slightly different. Its server is more like a router, recording the network path from device A to device B. Then notify both parties of the path, and try to let AB connect by itself. In other words, Zerotier sets up a virtual local area network, and all devices communicate with each other in the virtual local area network.
How to use: Refer to (the last chapter of this video)
Hardcore】Public network access? Intranet penetration! Get started with zero experience!

insert image description here

IPv6

"Every grain of sand on Earth has its own IP address"

insert image description here

Guess you like

Origin blog.csdn.net/verse_armour/article/details/128885958