Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
When networks fail, hams to the rescue
Alliance to promote Windows-managed Macs in enterprise
Lockheed Martin gets $89 million to converge DoD distribution networks
Clothes don't make this man: Sweatshirt helps nail Citibank card scammer
Microsoft readies new try for Yahoo
Gartner: Seven cloud-computing security risks
Autonomy, Endeca rate among top enterprise search vendors
Barracuda countersues Trend Micro in patent case
Mozilla's Firefox 3 sets geeky world record
Microsoft SharePoint popularity comes with issues
IBM mainframe acquisition raises antitrust concerns
Diary of a deliberately spammed housewife
Report: Tech giants forming 'patent troll' alliance
Trojan lurks, waiting to steal admin passwords
California enacts cell-phone driving ban
LANs /

Protocol helps stretch IPv4 addresses

Related linksToday's breaking news
Send to a friendFeedback


IPv4, the current version of IP, supports more than four billion addresses. Considering the Internet's phenomenal growth, however, that represents a relatively meager allotment.

To extend the reach of the IPv4 address space, companies have turned to using private IPv4 addresses through a public-to-private address translation technique known as network address translation (NAT).

But this method has a number of limitations. So a new technique called Realm-Specific Internet Protocol (RSIP) promises to pick up where NAT leaves off.


Diagram of how it works

NAT works by using the several million private addresses that have been put aside by the Internet Engineering Task Force, turning a public IP address such as 192. 156.136.22 into a private address, such as 10.0.0.4, for delivery to a user's PC. Private IP addresses cannot be "seen" by the Internet, and therefore may be reused by various enterprise networks.

In conjunction with a NAT-enabled gateway or router device, a privately addressed network may hide hundreds or thousands of hosts behind a single public address. The NAT device differentiates among the PCs by translating their port numbers into unique values.

But NAT is limited by applications such as streaming media that transmit IP addresses or port numbers in the payloads of packets. Such applications require that NAT take on application-specific knowledge and perform additional computation.

Worse, because NAT typically resides in a boundary router between private and public networks, it can't function with IP Security (IPSec), the popular encryption technology for virtual private networks. IPSec requires true end-to-end handshaking in order to set up initial encryption rules. Once encrypted at a client system, IPSec packets cannot be modified - or recognized - by NAT.

Like NAT, RSIP translates between public and private IP addresses. But instead of requiring a boundary router to translate, RSIP uses a simple protocol between a user's desktop PC and a boundary router to perform preparatory signaling. Through this signaling, the PC is able to prepare each packet in a way that removes the translation burden.

The RSIP protocol works via a simple challenge-response structure, and employs a vocabulary consisting of "parameters" and "messages."

Operation begins when RSIP client software in a PC signals the RSIP server software in a boundary router or gateway. Through this exchange, the RSIP client requests a public IP address, plus one or more of the router/gateway's ports.

In reply, the router/gateway's RSIP server software assigns a public IP address and one or more port numbers, in addition to lease time, tunnel type and other parameters.When the packet hits the RSIP server/ gateway, the packet's uniqueness is identified by the combination of assigned IP address and port numbers.

As with NAT, the RSIP server uses a reserved IP address, such as 10.0.0.4, for its own internal-enterprise addressing scheme. But unlike NAT, the boundary device gateway does not have to possess the intelligence to perform the translation; instead, the RSIP server/gateway sees the information it needs in the packet header, then consults its RSIP table to determine where the packet should go.

It's clear that RSIP represents a big improvement over NAT. For instance, with a simple extension, RSIP can support end-to-end IPSec, even though IPSec encrypts port numbers. Still, the two techniques have much in common, and this will work to the advantage of users.

RSIP promises two important advantages. Its close ties with the NAT addressing scheme bring backward compatibility, a benefit to the thousands of NAT users who will prefer to migrate gracefully to RSIP. And because the RSIP protocol employs preparatory signaling, RSIP is suited to policy-driven networking.

diagram

Related Links

Mike Borella is a senior architect at 3com. He can be reached at mike borella@3com.com.

The next best thing to IPv6?
More on RSIP. Network World, 9/20/99.

Realm Specific IP: Protocol Specification
IETF draft.

Realm Specific IP: A Framework
IETF draft.

RSIP Support for End-to-end IPSEC
IETF draft.

IETF NAT working group

Microsoft stalls IPv6 progress
Next-generation IP protocol backers seek out Gates. Network World, 8/30/99.

IPv6 audio primer
Listen to an explanation of the protocol in RealAudio.

IETF IPv6 working group

The IPv6 Forum
Consortium of vendors, researchers and network providers. Site includes technical overviews.

Recent Network World articles about IPv6
From product news to standards work.

 
NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.