nsored Links
-->

Friday, April 13, 2018

Private network

Virtual Private Network (VPN)
src: hifibroadband.com

In the Internet addressing architecture, a private network is a network that uses private IP address space, following the standards set by RFC 1918 for Internet Protocol Version 4 (IPv4), and RFC 4193 for Internet Protocol Version 6 (IPv6). These addresses are commonly used for home, office, and enterprise local area networks (LANs). Private IP address spaces were originally defined in an effort to delay IPv4 address exhaustion, but they are also a feature of IPv6 where exhaustion is not an issue.

Addresses in the private space are not allocated to any specific organization and anyone may use these addresses without approval from a regional Internet registry. However, IP packets addressed from them cannot be transmitted through the public Internet, and so if such a private network needs to connect to the Internet, it must do so via a network address translator (NAT) gateway, or a proxy server.


Video Private network



Private IPv4 address spaces

The Internet Engineering Task Force (IETF) has directed the Internet Assigned Numbers Authority (IANA) to reserve the following IPv4 address ranges for private networks:

Administrators of private networks can assign networks and subnets from the above ranges.

Although the standard for A and B class networks specify 8 and 12 bit masks respectively, it is common to assign non standard masks, resulting in much more limited address spaces (e.g. 10.xx.yy.0/24, resulting in a 256 hosts company subnet). This is done for scalability and security. The company sets-up intelligent gateways between their subnets.


Maps Private network



Dedicated space for carrier-grade NAT deployments

In April 2012, IANA allocated 100.64.0.0/10 for use in carrier-grade NAT scenarios. This address block should not be used either on private networks or on the public Internet: it is intended only for use within the internal operations of carrier networks. The size of the address block (222, approximately 4 million, addresses) was selected to be large enough to uniquely number all customer access devices for all of a single operator's points of presence in a large metropolitan area such as Tokyo.


What is VPN (Virtual Private Network) | How VPN works | VPN Types ...
src: www.learnabhi.com


Private IPv6 addresses

The concept of private networks has been extended in the next generation of the Internet Protocol, IPv6, and special address blocks are reserved.

The address block fc00::/7 is reserved by IANA for Unique Local Addresses (ULA). They are unicast addresses, but contain a 40-bit random number in the routing prefix to prevent collisions when two private networks are interconnected. Despite being inherently local in usage, the IPv6 address scope of unique local addresses is global.

The first block defined is fd00::/8, designed for /48 routing blocks, in which users can create multiple subnets as needed.

Examples:

A former standard proposed the use of site-local addresses in the fec0::/10 block, but because of scalability concerns and poor definition of what constitutes a site, its use has been deprecated since September 2004.


A virtual private network vpn - Bank of america 500 live stream
src: image.slidesharecdn.com


Link-local addresses

Another type of private networking uses the link-local address range. The validity of link-local addresses is limited to a single link; e.g. to all computers connected to a switch, or to one wireless network. Hosts on different sides of a bridge are also on the same link, whereas hosts on different sides of a router are on different links.

IPv4

In IPv4, link-local addresses are codified in RFC 6890 and RFC 3927. Their utility is in zero configuration networking when Dynamic Host Configuration Protocol (DHCP) services are not available and manual configuration by a network administrator is not desirable. The block 169.254.0.0/16 was allocated for this purpose. If a host on an IEEE 802 (Ethernet) network cannot obtain a network address via DHCP, an address from 169.254.1.0 to 169.254.254.255 may be assigned pseudorandomly. The standard prescribes that address collisions must be handled gracefully.

IPv6

In IPv6, link-local addresses are codified in RFC 4862. Their implementation is mandatory as various functions of the IPv6 protocol depend on them. The architecture defined in RFC 4291 sets aside the block fe80::/10 for IP address autoconfiguration.


VPN - Virtual Private Network - YouTube
src: i.ytimg.com


Common uses

The most common use of private addresses is in residential IPv4 networks, since most Internet service providers (ISPs) allocate only a single publicly routable IPv4 address to each residential customer, but many homes have more than one computer or other Internet connected device, such as smartphones. In this situation, a network address translator (NAT/PAT) gateway is usually used to provide Internet connectivity to multiple hosts.

Private addresses are also commonly used in corporate networks, which for security reasons, are not connected directly to the Internet. Often a proxy, SOCKS gateway, or similar devices are used to provide restricted Internet access to network-internal users.

In both cases, private addresses are often seen as enhancing network security for the internal network, since it is difficult for an Internet (external) host to connect directly to an internal system.


Virtual private network connection Stock Photo, Royalty Free Image ...
src: c8.alamy.com


Misrouting

It is common for packets originating in private address spaces to be misrouted onto the Internet. Private networks often do not properly configure DNS services for addresses used internally and attempt reverse DNS lookups for these addresses, causing extra traffic to the Internet root nameservers. The AS112 project attempted to mitigate this load by providing special blackhole anycast nameservers for private address ranges which only return negative result codes (not found) for these queries.

Organizational edge routers are usually configured to drop ingress IP traffic for these networks, which can occur either by misconfiguration, or from malicious traffic using a spoofed source address. Less commonly, ISP edge routers drop such egress traffic from customers, which reduces the impact to the Internet of such misconfigured or malicious hosts on the customer's network.


3D Rendered Illustration. Virtual Private Network Connection ...
src: previews.123rf.com


Merging private networks

Since the private IPv4 address space is relatively small, many private IPv4 networks unavoidably use the same address ranges and hence the same addresses. This can create a problem when merging such networks, as multiple devices are likely to have the same address. In this case, networks or hosts must be renumbered, often a time-consuming task, or a network address translator must be placed between the networks to translate or masquerade the duplicate addresses.

For IPv6, RFC 4193 defines Unique Local Addresses, providing an extremely large private address space from which each organisation can randomly or pseudo-randomly allocate its own 40-bit prefix, each of which allows 65536 organisational subnets. With space for about one trillion (1012) prefixes, it is extremely unlikely that two network prefixes in use by different organisations are the same, provided each of them was allocated randomly, as specified in the standard. When two such private IPv6 networks are connected or merged, the risk of an address conflict is therefore virtually absent.


Dropbox Expands Global Private Network to Accelerate Sync Speeds ...
src: aem.dropbox.com


Private use of other reserved addresses

Despite official warnings, historically some organizations have used other parts of the reserved IP address space for their internal networks.


Learn Cryptography - Virtual Private Networks (VPN)
src: learncryptography.com


RFC documents

  • RFC 1918 - "Address Allocation for Private Internets"
  • RFC 2036 - "Observations on the use of Components of the Class A Address Space within the Internet"
  • RFC 2050 - "Internet Registry IP Allocation Guidelines"
  • RFC 2101 - "IPv4 Address Behaviour Today"
  • RFC 2663 - "IP Network Address Translator (NAT) Terminology and Considerations"
  • RFC 3022 - "Traditional IP Network Address Translator (Traditional NAT)"
  • RFC 3330 - "Special-Use IPv4 Addresses" (superseded)
  • RFC 3879 - "Deprecating Site Local Addresses"
  • RFC 3927 - "Dynamic Configuration of IPv4 Link-Local Addresses"
  • RFC 4193 - "Unique Local IPv6 Unicast Addresses"
  • RFC 5735 - "Special-Use IPv4 Addresses" (superseded)
  • RFC 6598 - "Reserved IPv4 Prefix for Shared Address Space"
  • RFC 6890 - "Special-Purpose IP Address Registries"

Editable Pack Of Link, Virtual Private Network, Modem And Other ...
src: us.123rf.com


See also

  • Carrier-grade NAT
  • Heartbeat network
  • Intranet, a private network
  • Localhost
  • Reserved IP addresses
  • Unique Local Address (IPv6 private network prefix)

VPN, Virtual Private Network Icons, Blue Color Theme Royalty Free ...
src: previews.123rf.com


Notes


Explainer: What is a virtual private network (VPN)?
src: 3c1703fe8d.site.internapcdn.net


References

Source of the article : Wikipedia