Firewall NAT mapping - port mapping - from scratch to learn RouterOS Series 05

This tutorial uses:

There IPV4 public IP network companies need to site, CRM, ERP and other server can access the public network.

So what is the port mapping (Port-Forwarding), it is to look at NAT and NAPT.

NAT is network address translation.

NAPT is Network Address Port Translation.

NAT is used for address conversion of the address, such as the network address of the public network address translation. And later found that the egg is not used, the number is far enough. Then we explore the TCP / IP protocol, with its 16bit port capacity, the innovative use of technology NAPT, an IP can be expanded to 65,535 ports, and finally get through a number of devices outbreak.

So this port mapping and what does it matter?

We use the computer when the Internet is based on access to the port, the port can be reused, referred to as port multiplexing.

If we use the 65162 port 443 port to access the server, router help us record this information (NAPT mapping table) and NAPT evacuation out outside the network. ××× will be returned to us by 443 data port 65162, NAPT router and then to help us back to the computer, so we can now communicate.


webp

NAPT router table:


webp

But the port is temporary, we refresh the page will refresh the local port, and replaced with a different port, the original port 65162, waiting may be used again. Thus, the router so tirelessly to help us in exchange for going, we will be able to have enough ports to access the network.

For a direction, we as the application server, the server listens on a specific port, use for customers. Then we need to put this particular port permanently points to the server, to ensure that customers can find the address and port of the server. This is the port mapping.

So RouterOS port mapping is how to achieve?

Please have topology:


webp

Website Intranet IP: 192.168.11.252, Web site port 80

Router public network IP: 100.1.1.121

Win7 computer IP: 100.1.1.254

At this point we need to access our WIN7 computer network server, it is how to achieve?

First we need to open our ports to the external network to 80 by NAPT.

In RouterOS inside, click IP> Firewall, select NAT, the new rule:

webp

Then (Action) inside the Action,

webp

This time, we put the public network port 80 permanently assigned to the 80-port network site,

Test results are as follows:

webp

Why did not display port it? This is because the HTTP protocol is the default port 80. So the browser does not display your port 80, but if you map the public IP address of the port modified to 8888, this time you can show your port.

webp


webp

Also to note is that domestic ISP environment, if you do not go for the record, then port 80, 8080 and 443 are no way to use, because in the operator's network there, you do not like tongguanju application for the record, these ports are closed, and this time we will use other ports come and go instead.

The above is a port mapping tutorial ROS by this operation, we can go to remote desktop mapping, mapping of other services, but suggest that you map network port when the attention of the public, be sure to choose some high port mapping, and why? A later date in security papers.


Guess you like

Origin blog.51cto.com/13796759/2426500