Peer-to-Peer (P2P) communication across middleboxes(术语篇)[13]

[入库:2005年8月18日] [更新:2007年3月24日]

本文简介:选择自 hxhbluestar 的 blog

受限制的锥形nat会对传入的数据包进行筛选,当内部主机发出外出的会话时,nat会记录这个外部主机的ip地址信息,所以,也只有这些有记录的外部ip地址,能够将信息传入到nat内部,受限制的锥形nat 有效的给防火墙提炼了筛选包的原则——即限定只给那些已知的外部地址传入信息到nat内部。

 

port-restricted cone nat

a port-restricted cone nat, in turn, only forwards an incoming packet if its external ip address and port number match those of an external endpoint to which the internal host has previously sent outgoing packets. a port-restricted cone nat provides internal nodes the same level of protection against unsolicited incoming traffic that a symmetric nat does, while maintaining a private port's identity across translation.

端口受限制的cone nat

本文关键:Peer-to-Peer (P2P) communication across middleboxes(术语篇)
 

本站最佳浏览方式为 分辨率 1024x768 IE 6.0(或更高版本的 IE浏览器)

go top