About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
PRODUCT REVIEWS GUIDE    REVIEWS    ANALYSES    SPECIAL REPORTS 
 

TEST CENTER

 
NAT Traversal connects

By Mandy Andress
February 15, 2002


THE FAST-GROWING use of the Internet led to a shortage of IP addresses. To deal with this problem, the Internet Engineering Task Force (IETF) defined NAT (Network Address Translation), which is a way to convert private IP addresses to publicly routable Internet addresses, allowing organizations to minimize the number of Internet IP addresses they need. Thanks to NAT, companies can now connect thousands of systems to the Internet behind one public IP address.

   ADVERTISEMENT
  

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  IE 7 bug reopens debate over patch responsibilities
»  Woman ordered to pay for file-sharing will appeal
»  McAfee to buy SafeBoot for $350M
»  Security RSS feed 

IDG ENTERPRISE NETWORK
Research Reports  (CIO)
Ask the Expert  (CIO)

TOP NEWS 


IT SOLUTION SEARCH
NAT works in two ways. Static NAT maps each private address to a public address. With NAPT (Network Address Port Translation), both IP address and port are translated, allowing many systems to share a single public IP address. Although NAT provides many benefits, some applications, such as IPsec VPNs, peer-to-peer communications, and video streaming, do not work well through NAT.

With IPsec VPNs, the problem involves ensuring packet integrity. When a packet passes through a NAT device, the original IP address is modified. This is a no-no for IPsec, because any modification of the packet will result in a failed integrity check and prevent the VPN tunnel from being created. Therefore, IPsec and NAT can function together only when NAT occurs before the packet is encrypted. And while this typically works fine in gateway-to-gateway communications, remote access solutions are problematic because the IPsec VPN client on a remote laptop will encrypt the packet before it travels to the NAT device, subsequently breaking the IPsec VPN connection.

To enable IPsec VPNs to work with NAT devices, some of the leading technology companies created a solution coined NAT Traversal, which is currently an IETF draft standard. Two approaches to NAT Traversal were developed, one by SSH Communications and the other by F-Secure, Cisco Systems, Nortel Networks, and Microsoft. In March 2001, these two solutions were combined into one (see www.ietf.org/internet-drafts/draft-ietf-ipsec-nat-t-ike-01.txt). The main technology behind this solution is UDP (User Datagram Protocol) encapsulation, wherein the IPsec packet is wrapped inside a UDP/IP header, allowing NAT devices to change IP or port addresses without modifying the IPsec packet.

Negotiating NAT

For NAT Traversal to work properly, two things must occur. First, the communicating VPN devices must support the same method of UDP encapsulation. Second, all NAT devices along the communication path must be identified.

According to the IETF draft standard, IPsec devices will exchange a specific, known value to determine whether or not they both support NAT Traversal. (Currently, this value is draft-ietf-ipsec-nat-t-ike-00.) If the two VPN devices agree on NAT Traversal, they next determine whether or not NAT or NAPT occurs anywhere on the communications path between them. NAT devices are determined by sending NAT-D (NAT Discovery) packets. Both end points send hashes of the source and destination IP addresses and ports they are aware of. If these hashes do not match, indicating that the IP address and ports are not the same, then the VPN devices know a NAT device exists somewhere in between.

Usually, NAT assignments last for a short period of time and are then released. For IPsec to work properly, the same NAT assignment needs to remain intact for the duration of the VPN tunnel. NAT Traversal accomplishes this by requiring any end point communicating through a NAT device to send a "keepalive" packet, which is a one-byte UDP packet sent periodically to prevent NAT end points from being remapped midsession.

All NAT Traversal communications occur over UDP port 500. This works great because port 500 is already open for IKE (Internet Key Exchange) communications in IPsec VPNs, so new holes do not need to be opened in the corporate firewall. This solution does add a bit of overhead to IPsec communications; namely, 200 bytes is added for the Phase 1 IKE negotiation and each IPsec packet has about an additional 20 bytes.

Testing Traversal

We attempted to use NAT Traversal to connect a remote access system running SafeNet's latest VPN client software and sitting behind a Linksys SOHO (Small Office/Home Office) firewall performing NAT and a Netscreen VPN gateway with NAT Traversal support built-in. No configuration changes were required on the client side, and configuration on the Netscreen device was minimal. When configuring the VPN gateway, all we had to do was check one box to enable NAT Traversal. We established a VPN tunnel with absolutely no problems. Reviewing the logs on both the client and gateway, we noted the exchanges establishing NAT Traversal support and discovering a NAT device in the communications path.

NAT Traversal is the long-awaited solution to one of the major issues with IPsec VPNs, but it does not solve everyone's problems. For example, private address space can overlap and create routing issues, and NAT Traversal is not supported with AH (Authenticated Header) IPsec connections. Nevertheless, by enabling IPsec VPNs to work with NAT, NAT Traversal allows companies to improve the security of remote connections.




  BOTTOM LINE
NAT Traversal
EXECUTIVE SUMMARY
NAT and IPsec VPNs work together as long as NAT occurs before the IPsec packet is encrypted. But because remote access clients typically encrypt the packet before sending it to a NAT device, IPsec VPNs and NAT usually don't mix. NAT Traversal can help alleviate the NAT issues with IPsec VPNs, making them easier to secure and deploy.

TEST CENTER PERSPECTIVE
Minimum configuration requirements and ease of use make NAT Traversal a must for organizations using IPsec VPNs. Look for NAT Traversal support in Netscreen appliances and other leading firewalls and VPN gateways.


RELATED SUBJECTS

Security
Networking


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» IT Compliance Conference: Nov. 5-7 in San Diego
Best Practices, Peer Experiences, & Expert Advice for Building a Defensible IT Compliance Program
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» IT Audit Checklists
Prepare for your next internal IT audit. Checklists cover security, risk management, PCI, and more.
» FREE White Paper: Mitigating Rock Phish Attacks
Standard anti-phishing methods cannot defeat complex Rock Phish attacks. Learn how to fight back...
» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no