NetFilter
[Top] [All Lists]

Re: NAT addresses - RFC or tradition?

To: jpb@entel.ca
Subject: Re: NAT addresses - RFC or tradition?
From: Leonardo Rodrigues Magalhães <leolistas@solutti.com.br>
Date: Tue, 22 May 2007 17:02:52 -0300
Cc: netfilter@lists.netfilter.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <001c01c79ca7$0c1717e0$5a05a8c0@nisgaa.net>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
References: <001c01c79ca7$0c1717e0$5a05a8c0@nisgaa.net>
Sender: netfilter-bounces@lists.netfilter.org
User-agent: Thunderbird 1.5.0.10 (Windows/20070221)


Paul Blondé escreveu:
I've noticed that a lot of people use the 192.168.X.X subnet for internal
networks, is this (and the less-used 10-series) a requirement of some RFC,
or a recommendation that has become tradition?

We are using a completely different subnet, something similar to (for
example) 42.127.129.X to further obfuscate the internal network from
outside. This, and many other examples, produces a class-A subnet mask (some
produce a class-B) when entered in WinXP's TCP/IP dialog, although the
actual mask we use with it is class-C.

Is this a no-no? Will it break our server's IPTables when communicating with
it? Am I in for a lot of trouble? The addresses don't seem to cause any
problems, but I don't want this to jump up and bite us in the bottom
sometime down the road.

Yes, those 'reserved' IP addresses are declared by RFC 1918. Please check:

http://tools.ietf.org/html/rfc1918
http://en.wikipedia.org/wiki/Private_network

Your network will work with no problems, except if you had to access some far-far-far away network which uses your local addresses, which should never be used as local ones.

--


        Atenciosamente / Sincerily,
        Leonardo Rodrigues
        Solutti Tecnologia
        http://www.solutti.com.br

        Minha armadilha de SPAM, NÃO mandem email
        gertrudes@solutti.com.br
        My SPAMTRAP, do not email it






<Prev in Thread] Current Thread [Next in Thread>