NATting with IPfilter

Guido van Rooij
Madison Gurkha

<guido@madison-gurkha.com>

Deze lezing zal in het Nederlands worden gegegeven!
This presentation will be in Dutch!

IPfilter is probably the most popular open source TCP/IP filtering engines. Since its birth, some 7 years ago, IPfilter has grown to a very feature rich package. One of these powerfull features is Network Address Translation (NAT). With the scarsity of IP addresses, NATting has become a hot item in the last couple of years.

This presentation will focus on the NAT capabilities of Ipfilter. Doing NAT opens the way to new NAT alike features and a number of those have been implemented in IPfilter.
Apart from explaining these features, useful real world applications of those features will be mentioned. These include:

  • different forms of NATting (simple mapping, block mapping, port mapping, bidirectional mapping)
  • Redirection
  • In kernel proxying
  • Transparent proxying (e.g. with Squid and the Firewall Toolkit)
  • Server load balancing.
Guido van Rooij is married and has 3 children. In his spare time, he co-runs Madison Gurkha BV, the Security and Open Source consulting firm.
He graduated in Discrete Mathematics at Eindhoven University of Technology and started working as software developer on medical systems, OCR equipment and numerical controls. In 1995 he joined Philips to work on Internet security. Among others, he has been in charge with development and operations of the Philips firewalls. He is co-founder of the Eindhoven Digital City and Internet Access Eindhoven. Furthermore, he was security officer of FreeBSD and part of the FreeBSD core team.


Last modified: August 10, 2000 (mr)
[Go to: Backup architecturen in het moderne data centrum (Edmond van As)] [Go to: Inleiding] [Go to: Index]