mixi¤Ç¼ñÌ£¤ÎÏäò¤·¤è¤¦

mixi¥³¥ß¥å¥Ë¥Æ¥£¤Ë¤Ï270Ëü¤òĶ¤¨¤ë¼ñÌ£¥³¥ß¥å¥Ë¥Æ¥£¤¬¤¢¤ë¤è
¥í¥°¥¤¥ó¤â¤·¤¯¤ÏÅÐÏ¿¤ò¤·¤ÆƱ¤¸¼ñÌ£¤Î¿Í¤È½Ð²ñ¤ª¤¦¢ö

NAT Ž±ŽÄŽÞŽÚŽ½ÊÑ´¹

  • mixi¥Á¥§¥Ã¥¯
  • ¤³¤Î¥¨¥ó¥È¥ê¡¼¤ò¤Ï¤Æ¤Ê¥Ö¥Ã¥¯¥Þ¡¼¥¯¤ËÄɲÃ
¾ÜºÙ 2016ǯ11·î4Æü 13:21¹¹¿·

¡¢
¥Í¥Ã¥È¥ï¡¼¥¯¥¢¥É¥ì¥¹ÊÑ´¹¡Ê¥Í¥Ã¥È¥ï¡¼¥¯¥¢¥É¥ì¥¹¤Ø¤ó¤«¤ó¡Ë¡¢NAT¡ÊNetwork Address Translation¡Ë¤È¤Ï¡¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥×¥í¥È¥³¥ë¤Ë¤è¤Ã¤Æ¹½ÃÛ¤µ¤ì¤¿¥³¥ó¥Ô¥å¡¼¥¿¥Í¥Ã¥È¥ï¡¼¥¯¤Ë¤ª¤¤¤Æ¡¢¥Ñ¥±¥Ã¥È¥Ø¥Ã¥À¤Ë´Þ¤Þ¤ì¤ëIP¥¢¥É¥ì¥¹¤ò¡¢Ê̤ÎIP¥¢¥É¥ì¥¹¤ËÊÑ´¹¤¹¤ëµ»½Ñ¤Ç¤¢¤ë¡£

¥×¥é¥¤¥Ù¡¼¥È¥Í¥Ã¥È¥ï¡¼¥¯´Ä¶­²¼¤Î¥Û¥¹¥È¤«¤é¡¢¥°¥í¡¼¥Ð¥ë¥¢¥É¥ì¥¹¤ò»ý¤Ä¥²¡¼¥È¥¦¥§¥¤¤òÄ̤·¤Æ¡¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤Ë¥¢¥¯¥»¥¹¤¹¤ë¤¿¤á¤ËÍøÍѤµ¤ì¤ë¤³¤È¤¬Â¿¤¤¡£¤Þ¤¿¡¢IP¥¢¥É¥ì¥¹¤Ë²Ã¤¨¡¢¥Ý¡¼¥ÈÈÖ¹æ¤ÎÊÑ´¹¤ò¹Ô¤¦¤â¤Î¤òNAPT(Network Address Port Translation)¤È¸Æ¤Ö¡£º£Æü¤Ç¤Ï¡¢NAT¤È¸À¤¨¤ÐNAPT¤Î¤³¤È¤ò»Ø¤¹¤Î¤¬°ìÈÌŪ¤Ç¤¢¤ë¡£





Ìܼ¡
[Èóɽ¼¨] 1 µ»½Ñ¤Î³µÍ× 1.1 IP ¥¢¥É¥ì¥¹¤Î¸Ï³é
1.2 ưŪ NAT
1.3 ÀÅŪ NAT
1.4 NAT¤ÈNAPT
1.5 ¥»¥­¥å¥ê¥Æ¥£
1.6 ÈãȽ

2 NAT¤ÎʬÎà
3 ´ØÏ¢µ»½Ñ 3.1 Connection Trackingµ¡Ç½
3.2 GapNATµ¡Ç½
3.3 UPnP ¤Îµ¬Äꤹ¤ëInternet Gateway Device(IGD)

4 IPv4 IPv6´Ö NAT
5 ´ØÏ¢¹àÌÜ
6 »²¾È
7 ³°Éô¥ê¥ó¥¯


µ»½Ñ¤Î³µÍ× [ÊÔ½¸]

IP ¥¢¥É¥ì¥¹¤Î¸Ï³é [ÊÔ½¸]

¸µÍè¡¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤ËÀܳ¤µ¤ì¤ëÁ´¤Æ¤Î¥ë¡¼¥¿¤ä¥Û¥¹¥È¤Ë¤Ï¡¢¤½¤ì¤¾¤ì¸ÇÍ­¤ÎIP¥¢¥É¥ì¥¹¡Ê¥°¥í¡¼¥Ð¥ëIP¥¢¥É¥ì¥¹¡Ë¤¬³ä¤êÅö¤Æ¤é¤ì¤Æ¤¤¤¿¡£¤·¤«¤·¡¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤ËÀܳ¤µ¤ì¤ë¥Û¥¹¥È¤¬Ãø¤·¤¯Áý¤¨¤¿¤¿¤á¡¢Ìó43²¯¸Ä¤ò¾å¸Â¤È¤¹¤ëIP¥¢¥É¥ì¥¹¤Ï¸Ï³é¤¹¤ë¤è¤¦¤Ë¤Ê¤Ã¤¿¡£¤³¤¦¤·¤¿¾õ¶·¤ØÂбþ¤¹¤ë¤¿¤á¡¢LANÆâ¤Î¥Û¥¹¥È¤Ë¤Ï¥×¥é¥¤¥Ù¡¼¥ÈIP¥¢¥É¥ì¥¹¤ò³ä¤êÅö¤Æ¡¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤ËÀܳ¤¹¤ë¤È¤­¤À¤±¥°¥í¡¼¥Ð¥ëIP¥¢¥É¥ì¥¹¤ò»ÈÍѤ¹¤ëµ»½Ñ¤¬³«È¯¤µ¤ì¤¿¡£¤³¤Î¤È¤­¤ËÍѤ¤¤é¤ì¤ëµ»½Ñ¤¬NAT¤Ç¤¢¤ë¡£

¥¢¥á¥ê¥«°Ê³°¤Î¹ñ¡¢Î㤨¤ÐÆüËܤʤɤǤϳä¤êÅö¤Æ¤é¤ì¤¿ IP ¥¢¥É¥ì¥¹¤ËÈæ¤Ù¤Æ¥³¥ó¥Ô¥å¡¼¥¿¤ÎÉáµÚ¤¬Ãø¤·¤¤¤¿¤á¡¢IP ¥¢¥É¥ì¥¹¤¬ÉÔ­¤·¤ä¤¹¤¤¡£ºÇ¶á¤Îͽ¬¤Ë¤è¤ì¤Ð 2011 ǯ¤³¤í¤Ë IP ¥¢¥É¥ì¥¹¤¬¸Ï³é¤¹¤ë¤È¤¤¤ï¤ì¤Æ¤¤¤ë¡£¤·¤¿¤¬¤Ã¤Æ¡¢¤³¤ì¤é¤Î¹ñ¤Ë¤ª¤¤¤Æ¤ÏNAT¤ÏÆä˽ÅÍ×À­¤¬¹â¤¤¤È¤¤¤¨¤ë¡£ÆüËܸþ¤±¤ËȯÇ䤵¤ì¤Æ¤¤¤ë ADSL ¤ä FTTH ¤Ê¤É¤ËÂбþ¤·¤¿¥Ö¥í¡¼¥É¥Ð¥ó¥É¥ë¡¼¥¿¤Ë¤ª¤¤¤Æ¤Ï¡¢¶È̳ÍÑ¡¢²ÈÄíÍѤòÌä¤ï¤ºNATµ¡Ç½¤ò»ý¤Ã¤Æ¤¤¤ë¤³¤È¤¬Â¿¤¤¡£

ưŪ NAT [ÊÔ½¸]

ưŪ NAT (¥À¥¤¥Ê¥ß¥Ã¥¯ NAT) ¤È¤Ï¡¢LAN ÆâÉô¤Î IP ¥¢¥É¥ì¥¹¤ò¤¢¤é¤«¤¸¤áÍÑ°Õ¤µ¤ì¤¿³°Éô IP ¥¢¥É¥ì¥¹¤ÎÃæ¤Î 1 ¸Ä¤òÁªÂò¤·¤Æ¤½¤Î IP ¥¢¥É¥ì¥¹¤ËưŪ¤Ë¥Þ¥Ã¥×¤¹¤ëµ»½Ñ¤Î¤³¤È¤Ç¤¢¤ë¡£Æ°Åª NAT ¤Ï¥»¥­¥å¥ê¥Æ¥£¤äÉÔ­¤¹¤ë IP ¥¢¥É¥ì¥¹¤ÎÌäÂê²ò·è¤ËÌò¤ËΩ¤Ä¤¬¡¢IP ¥¢¥É¥ì¥¹¤¬¸ÇÄꤵ¤ì¤Ê¤¤¤È¤¤¤¦ÌäÂêÅÀ¤¬¤¢¤ë¡£Î㤨¤Ð¡¢LAN ÆâÉô¤Î¥µ¡¼¥Ð¤ò¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤Ê¤É¡¢³°Éô¤«¤é»²¾È¤¹¤ëɬÍפ¬À¸¤¸¤¿¾ì¹ç¡¢³°Éô¤«¤é»²¾È¤¹¤ë¤¿¤á¤Ë¤Ï¥°¥í¡¼¥Ð¥ë IP ¥¢¥É¥ì¥¹¤¬É¬ÍפÀ¤¬¡¢Æ°Åª NAT ¤Ç¤Ï²ò·è¤Ç¤­¤Ê¤¤¡£

ÀÅŪ NAT [ÊÔ½¸]

ÀÅŪ NAT (¥¹¥¿¥Æ¥£¥Ã¥¯ NAT) ¤È¤Ï¡¢LAN ÆâÉô¤Î IP ¥¢¥É¥ì¥¹¤ò¾ï¤ËƱ°ì¤Î³°Éô¤Î IP ¥¢¥É¥ì¥¹¤ËÀÅŪ¤Ë¥Þ¥Ã¥×¤¹¤ëµ»½Ñ¤Î¤³¤È¤Ç¤¢¤ë¡£¤³¤Îµ»½Ñ¤ò»ÈÍѤ¹¤ì¤Ð¡¢LAN ¤Î³°Éô¤«¤é¾ï¤ËƱ°ì¤Î IP ¥¢¥É¥ì¥¹¤ò»ØÄꤹ¤ë¤³¤È¤Ë¤è¤Ã¤ÆÆâÉô¥µ¡¼¥Ð¤Ë¥¢¥¯¥»¥¹¤¹¤ë¤³¤È¤¬¤Ç¤­¤ë¡£

NAT¤ÈNAPT [ÊÔ½¸]

¸½ºß¤Ç¤Ï¡¢¥×¥é¥¤¥Ù¡¼¥ÈIP¥¢¥É¥ì¥¹¤È¥°¥í¡¼¥Ð¥ëIP¥¢¥É¥ì¥¹¤ÎÊÑ´¹¤Ë²Ã¤¨¤Æ¥Ý¡¼¥ÈÈÖ¹æ¤âÊÑ´¹¤Ç¤­¤ëNAPT¤¬ÍѤ¤¤é¤ì¤ë¤³¤È¤¬Â¿¤¤¡£NAT¥ª¡¼¥Ð¡¼¥í¡¼¥É¡¢¥ª¡¼¥Ð¡¼¥í¡¼¥ÉÊÑ´¹¡¢PAT¡ÊPort Address Translation¡¢Cisco Systems¤Ë¤è¤ë¸Æ¾Î¡Ë¡¢IP¥Þ¥¹¥«¥ì¡¼¥É¡ÊLinux¤Ë¤ª¤±¤ëNAPT¤Î¼ÂÁõ̾¤«¤é¡£¥Þ¥¹¥«¥ì¡¼¥É¡Êmasquerade¡Ë¤Ï¡¢²¾ÌÌÉñƧ²ñ¤Î°ÕÌ£¡Ë¤Ê¤É¤È¤â¸Æ¤Ð¤ì¤ë¡£

¸µÍè¤ÎNAT¤Ï¡¢Á÷¼õ¿®¤¹¤ë¥Ñ¥±¥Ã¥È¾å¤ÎIP¥¢¥É¥ì¥¹¤À¤±¤ò¼±Ê̤·¤ÆÊÑ´¹¤¹¤ë¤â¤Î¤Ç¤¢¤ë¤¿¤á¡¢Ê£¿ô¤Î¥Û¥¹¥È¤«¤éƱ»þ¤Ë¥í¡¼¥«¥ë³°¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤ËÀܳ¤·¤è¤¦¤È¤¹¤ë¤È¡¢¥í¡¼¥«¥ë¤Î¥Û¥¹¥È¿ô¤ÈƱ¿ô¤Î¥°¥í¡¼¥Ð¥ë¥¢¥É¥ì¥¹¤¬É¬Íפˤʤ롣NAPT¤Ç¤Ï¡¢IP¥¢¥É¥ì¥¹¤Ë²Ã¤¨¤Æ¥Ý¡¼¥ÈÈÖ¹æ¤Î¼±Ê̤äÊÑ´¹¤ò¤¹¤ë¤³¤È¤Ç¡¢Ê£¿ô¤Î¥Û¥¹¥È¤«¤é¥í¡¼¥«¥ë³°¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤ËÀܳ¤¹¤ëºÝ¡¢°Û¤Ê¤ë¥í¡¼¥«¥ë¥¢¥É¥ì¥¹¤òƱ°ì¤Î¥°¥í¡¼¥Ð¥ë¥¢¥É¥ì¥¹ÇÛ²¼¤Î°Û¤Ê¤ë¥Ý¡¼¥È¤È¤·¤Æɽ¸½¤·¡¢É¬Íפʥ°¥í¡¼¥Ð¥ë¥¢¥É¥ì¥¹¤Î¿ô¤ò¸º¤é¤¹¤³¤È¤¬¤Ç¤­¤ë¡£

¥»¥­¥å¥ê¥Æ¥£ [ÊÔ½¸]

NAT¤Ë¤Ï¡¢¥»¥­¥å¥ê¥Æ¥£¤ò¹â¤á¤ë¸ú²Ì¤â¤¢¤ë¡£¥°¥í¡¼¥Ð¥ëIP¥¢¥É¥ì¥¹¤ò¥×¥é¥¤¥Ù¡¼¥ÈIP¥¢¥É¥ì¥¹¤ËÊÑ´¹¤¹¤ë¤È¤­¤Ë¡¢¥Ñ¥±¥Ã¥È¥Õ¥£¥ë¥¿¥ê¥ó¥°¡Ê¥Ñ¥±¥Ã¥È(syn)¤Î¾ò·ï¤ò»ØÄꤷ¤ÆÀ©¸Â¡Ë¤¬¤Ç¤­¤ë¤¿¤á¤Ç¤¢¤ë¡£¼ÂºÝ¤Ë¤Ï¡¢¥×¥é¥¤¥Ù¡¼¥ÈIP¥¢¥É¥ì¥¹¤ò³ä¤êÅö¤Æ¤é¤ì¤¿¥Û¥¹¥È¤Ë¤Ï¡¢ÆÃÊ̤ÊÀßÄê¤ò¤·¤Ê¤¤¸Â¤ê³°Éô¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤«¤é¤ÏÀܳ¤Ç¤­¤Ê¤¤¤³¤È¤¬Â¿¤¤¡£¤³¤¦¤·¤¿ÆÃħ¤«¤é¡¢NAT¤Ï´Ê°×Ū¤Ê¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¤Î°ì¼ï¤È¹Í¤¨¤ë¤³¤È¤â¤Ç¤­¤ë¡£

ÈãȽ [ÊÔ½¸]

¤½¤Î°ìÊý¡¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤¬ËÜÍè·Ç¤²¤Æ¤¤¤¿¥Ô¥¢¡¦¥Ä¡¼¡¦¥Ô¥¢¤Ç¤ÎÀܳ¤ËÂФ¹¤ë¾ã³²¤Ë¤Ê¤ê¤¦¤ë¤È¤¤¤¦ÈãȽŪ¤Ê°Õ¸«¤â¤¢¤ë¡Ê¥¨¥ó¥É¥Ä¡¼¥¨¥ó¥ÉÀܳÀ­¡Ë¡£¤Þ¤¿¡¢FTP¤ä¡¢SIP¤Ê¤É¤ÎVoIP¤òµ¡Ç½¤µ¤»¤ë¤¿¤á¤Ë¤Ï¹©Éפ¬É¬Íפʾì¹ç¤â¤¢¤ë¡£

¤Þ¤¿¡¢Ê£¿ô¤Î¥í¡¼¥«¥ëIP¥¢¥É¥ì¥¹¤«¤é¤Î¥¢¥¯¥»¥¹¤ò¡¢1¤Ä¤Î¥°¥í¡¼¥Ð¥ëIP¥¢¥É¥ì¥¹¤Ç¶¦Í­¤·¤Æ¤¤¤ë¤¿¤á¡¢³°¤«¤é¤Ï¥í¡¼¥«¥ë¥Í¥Ã¥È¥ï¡¼¥¯Æâ¤Î¤É¤Î¥Î¡¼¥É¤¬¥¢¥¯¥»¥¹¤·¤¿¤Î¤«¤Þ¤Ç¤òÆÃÄꤹ¤ë¤³¤È¤Ï¤Ç¤­¤Ê¤¤¡£¤³¤Î¤¿¤á¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥«¥Õ¥§¤Ê¤É¤ÎÉÔÆÃÄê¿¿ô¤Î¿Í¤¬ÍøÍѤ¹¤ë¥¢¥¯¥»¥¹Ã¼Ëö¤«¤é¤Î¡¢°­°Õ¤Î¤¢¤ëÍøÍÑ¡ÊSPAM¹Ô°Ù¤ä·Ç¼¨ÈĹӤ餷¡¢¥Í¥Ã¥ÈÈȺá¤Ê¤É¡Ë¤¬¤Ê¤µ¤ì¤¿¾ì¹ç¡¢Æ¿Ì¾À­¤¬¹â¤¯ÆÃÄ꤬¤è¤êº¤Æñ¤Ë¤Ê¤ë¡£

NAT¤ÎʬÎà [ÊÔ½¸]

NAT¤Ï¥¢¥É¥ì¥¹¤ä¥Ý¡¼¥ÈÈÖ¹æ¤òÊÑ´¹¤¹¤ëÍÍ¡¹¤Ê»ÅÁȤߤ˼ÂÁõ¤µ¤ì¤Æ¤¤¤ë¡£¤½¤·¤Æ¡¢¤½¤ì¤¾¤ì¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎÄÌ¿®¥×¥í¥È¥³¥ë¤Ë°Û¤Ê¤Ã¤¿±Æ¶Á¤òµÚ¤Ü¤¹¡£IP¥¢¥É¥ì¥¹¤Î¾ðÊó¤ò»ÈÍѤ¹¤ë¤¤¤¯¤Ä¤«¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥×¥í¥È¥³¥ë¤Ï¥Þ¥¹¥«¥ì¡¼¥É¤ËÍѤ¤¤é¤ì¤ë³°Éô¤Î¥¢¥É¥ì¥¹¤ò·èÄꤹ¤ëɬÍפ¬¤¢¤ë¡£¤½¤·¤Æ¤µ¤é¤Ë¡¢¤·¤Ð¤·¤ÐÍ¿¤¨¤é¤ì¤¿NATµ¡´ï¤ËÍѤ¤¤é¤ì¤ë¥Þ¥Ã¥Ô¥ó¥°¤Î¼ïÎà¤òȯ¸«¤·¡¢Ê¬Îह¤ëɬÍפ¬¤¢¤ë¡£¤³¤Î¤¿¤á¤Ë¡¢Simple traversal of UDP over NATs (STUN) protocol ¤Ï³«È¯¤µ¤ì¤¿¡£¤½¤ì (STUN) ¤ÏNAT¤Î¼ÂÁõ¤òFull cone NAT¡¢Restricted cone NAT¡¢Port restricted cone NAT¡¢¤â¤·¤¯¤ÏSymmetric NAT[1][2] ¤ËʬÎष¡¢¤½¤ì(¤³¤ÎʬÎà)¤Ë±þ¤¸¤Æµ¡´ï¤ò¸¡ºº¤¹¤ë¤¿¤á¤Î1¤Ä¤Î¼êË¡¤òÄó°Æ¤·¤¿¡£¤·¤«¤·¤Ê¤¬¤é¡¢¤½¤Î¸å¤³¤ì¤é¤Î¼ê½ç¤Ï¥¹¥¿¥ó¥À¡¼¥É¥¹¥Æ¡¼¥¿¥¹¤«¤é½ü³°¤µ¤ì¤¿¡£¤Ê¤¼¤Ê¤é¤³¤ì¤é¤ÎÊýË¡¤ÏÉÔ´°Á´¤Ç¡¢Â¿¤¯¤Îµ¡´ï¤òÀµ¤·¤¯É¾²Á¤¹¤ë¤Ë¤ÏÉÔ½½Ê¬¤Ç¤¢¤ë¤ÈȽÌÀ¤·¤¿¤«¤é¤Ç¤¢¤ë¡£¿·¤·¤¤ÊýË¡¤Ï¡¡RFC 5389 (2008) ¤Ëµ­½Ò¤µ¤ì¤Æ¤ª¤ê¡¢STUN¤ÎƬʸ»ú¤Ï¸½ºß¡¢¤³¤Î»ÅÍͤο·¤·¤¤¥¿¥¤¥È¥ë¤òɽ¤¹: Session Traversal Utilities for NAT¡£



Full cone NAT(¤Þ¤¿¤Ï1ÂÐ1NAT) ÆâÉô¥¢¥É¥ì¥¹ (iAddr:port1) ¤Ï³°Éô¥¢¥É¥ì¥¹ (eAddr:port2) ¤Ë¥Þ¥Ã¥×¤µ¤ì¤¿»þÅÀ¤Ç¡¢iAddr:port1 ¤«¤éÍ褿Ǥ°Õ¤Î¥Ñ¥±¥Ã¥È¤Ï eAddr:port2 ¤«¤éÁ÷¤é¤ì¤ë¡£Ç¤°Õ¤Î³°Éô¥Û¥¹¥È¤Ï¥Ñ¥±¥Ã¥È¤ò eAddr:port2 °¸¤ËÁ÷¤ë¤³¤È¤Ë¤è¤Ã¤Æ iAddr:port1 ¤ËÁ÷¤ë¤³¤È¤¬¤Ç¤­¤ë¡£






Address-Restricted cone NAT ÆâÉô¥¢¥É¥ì¥¹ (iAddr:port1) ¤Ï³°Éô¥¢¥É¥ì¥¹ (eAddr:port2) ¤Ë¥Þ¥Ã¥×¤µ¤ì¤¿»þÅÀ¤Ç¡¢iAddr:port1 ¤«¤éÍ褿Ǥ°Õ¤Î¥Ñ¥±¥Ã¥È¤Ï eAddr:port2 ¤«¤éÁ÷¤é¤ì¤ë¡£³°Éô¥Û¥¹¥È (hostAddr:Ǥ°Õ) ¤Ï iAddr:port1 ¤¬ hostAddr:Ǥ°Õ ¤Ë¥Ñ¥±¥Ã¥È¤òÁ÷¤Ã¤¿¤³¤È¤¬¤¢¤ë¾ì¹ç¤Ë¤Î¤ß¡¢eAddr:port2 ¤Ë¥Ñ¥±¥Ã¥È¤òÁ÷¤ë¤³¤È¤Ë¤è¤Ã¤Æ¡¢¥Ñ¥±¥Ã¥È¤ò iAddr:port1 ¤ËÁ÷¤ë¤³¤È¤¬¤Ç¤­¤ë¡£"Ǥ°Õ" ¤Ï¥Ý¡¼¥ÈÈֹ椬²¿¤Ç¤â¤è¤¤¤È¤¤¤¦¤³¤È¤ò°ÕÌ£¤¹¤ë¡£






Port-Restricted cone NAT
Restricted cone NAT¤Î¤è¤¦¤Ë¿¶¤ëÉñ¤¦¤¬¡¢¥Ý¡¼¥ÈÈÖ¹æ¤âÀ©¸Â¤µ¤ì¤ë¡£
ÆâÉô¥¢¥É¥ì¥¹ (iAddr:port1) ¤Ï³°Éô¥¢¥É¥ì¥¹ (eAddr:port2) ¤Ë¥Þ¥Ã¥×¤µ¤ì¤¿»þÅÀ¤Ç¡¢iAddr:port1 ¤«¤éÍ褿Ǥ°Õ¤Î¥Ñ¥±¥Ã¥È¤Ï eAddr:port2 ¤«¤éÁ÷¤é¤ì¤ë¡£³°Éô¥Û¥¹¥È(hostAddr:port3) ¤Ï¡¢ iAddr:port1 ¤¬ hostAddr:port3 ¤Ë¥Ñ¥±¥Ã¥È¤ò°ÊÁ°¤ËÁ÷¤Ã¤¿¾ì¹ç¤Ë¤Î¤ß¡¢ eAddr:port2 ¤Ë¥Ñ¥±¥Ã¥È¤òÁ÷¤ë¤³¤È¤Ë¤è¤Ã¤Æ¡¢¥Ñ¥±¥Ã¥È¤ò iAddr:port1 ¤ËÁ÷¤ë¤³¤È¤¬¤Ç¤­¤ë¡£






Symmetric NAT Ʊ°ìÆâÉôIP¥¢¥É¥ì¥¹¤È¥Ý¡¼¥È¤«¤éÆÃÄê¤Î°¸ÀèIP¥¢¥É¥ì¥¹¤ËÂФ¹¤ëÍ×µá¤ÏÁ´¤Æ¡¢Í£°ì¤Î³°Éô¥½¡¼¥¹IP¥¢¥É¥ì¥¹¤È¥Ý¡¼¥È¤Ë¥Þ¥Ã¥×¤µ¤ì¤ë °Û¤Ê¤ë°¸Àè¤ËÂФ·¤Æ¤Ï¡¢Æ±°ìÆâÉô¥Û¥¹¥È¤¬¤¿¤È¤¨Æ±¤¸¥½¡¼¥¹¥¢¥É¥ì¥¹¤È¥Ý¡¼¥È¤Ç¥Ñ¥±¥Ã¥È¤òÁ÷¤Ã¤Æ¤â¡¢°Û¤Ê¤ë¥Þ¥Ã¥Ô¥ó¥°¤¬»È¤ï¤ì¤ë¡£
ÆâÉô¥Û¥¹¥È¤«¤é¤Î¥Ñ¥±¥Ã¥È¤ò¼õ¤±¼è¤Ã¤¿³°Éô¥Û¥¹¥È¤Î¤ß¤¬¥Ñ¥±¥Ã¥È¤òÁ÷¤êÊÖ¤¹¤³¤È¤¬¤Ç¤­¤ë¡£





¤³¤ÎÍѸì¤Ï¿¤¯¤Îº®Íð¤ò¾·¤¯¸¶°ø¤Ç¤¢¤Ã¤¿¡£¤Ê¤¼¤Ê¤é¤½¤ì¤Ï¸½¼Â¤ÎNAT¤Î¿¶¤ëÉñ¤¤¤òµ­½Ò¤¹¤ë¤Ë¤ÏÉÔŬÀڤǤ¢¤ë¤ÈȽÌÀ¤·¤¿¤«¤é¤Ç¤¢¤ë¡£[3] ¿¤¯¤ÎNAT¤Î¼ÂÁõ¤Ï¤³¤ì¤é¤Î¼ïÎà¤òÁȤ߹ç¤ï¤»¤Æ¤¤¤ë¡£½¾¤Ã¤ÆCone/Symmetric¤È¤¤¤¦ÍѸì¤ò»È¤¦Âå¤ï¤ê¤Ë¡¢¤½¤ì¤¾¤ì¸ÇÍ­¤ÎNAT¤Î¿¶¤ëÉñ¤¤¤Ë¸ÀµÚ¤¹¤ëÊý¤¬¤è¤¤¡£Æäˡ¢¤¿¤¤¤Æ¤¤¤ÎNATÊÑ´¹ÁõÃ֤ϳ°Éô¤Ë½Ð¤Æ¹Ô¤¯Êý¸þ¤Ø¤ÎÀܳ¤ËÂФ¹¤ëSymmetricNAT¤ÈÀÅŪ¥Ý¡¼¥È¥Þ¥Ã¥Ô¥ó¥°¤È¤òÁȤ߹ç¤ï¤»¤Æ¤¤¤ë¡£³°Éô¥¢¥É¥ì¥¹¤È¥Ý¡¼¥È¤ËÆþ¤Ã¤Æ¤¯¤ë¥Ñ¥±¥Ã¥È¤ÏÆÃÄê¤ÎÆâÉô¥¢¥É¥ì¥¹¤È¥Ý¡¼¥È¤Ë¥ê¥À¥¤¥ì¥¯¥È¤µ¤ì¤ë¡£¤¤¤¯¤Ä¤«¤ÎÀ½Éʤϡ¢Î㤨¤Ð²¿Â椫¤Î¥µ¡¼¥Ð¤Î´Ö¤ËÉé²Ù¤òʬ»¶¤¹¤ë¤¿¤á¤Ë¡¢Ê£¿ô¤ÎÆâÉô¥Û¥¹¥È¤Ë¥Ñ¥±¥Ã¥È¤ò¥ê¥À¥¤¥ì¥¯¥È¤Ç¤­¤ë¡£¤·¤«¤·¤Ê¤¬¤é¡¢¤³¤ì¤Ï¿¤¯¤ÎÁê¸ßÀܳ¥Ñ¥±¥Ã¥È¤¬Â¸ºß¤¹¤ë¤è¤¦¤Ê¡¢¤è¤êÊ£»¨¤ÊÄÌ¿®¤Î¾ì¹ç¤ËÌäÂê¤ò°ú¤­µ¯¤³¤¹¡£½¾¤Ã¤ÆÌÇ¿¤Ë»È¤ï¤ì¤ë¤³¤È¤Ï¤Ê¤¤¡£

¿¤¯¤ÎNAT¤Î¼ÂÁõ¤Ï¥Ý¡¼¥È°Ý»ýÀ߷פ˽¾¤¦¡£ ¤Û¤È¤ó¤É¤ÎÄÌ¿®¤Ë¤ª¤¤¤Æ¡¢NAT¤ÏÆâÉô¤È³°Éô¤Î¥Ý¡¼¥ÈÈÖ¹æ¤È¤·¤ÆƱ¤¸Ãͤò»È¤¦¡£ ¤·¤«¤·¤Ê¤¬¤é¡¢2¤Ä¤ÎÆâÉô¥Û¥¹¥È¤¬Æ±¤¸¥Ý¡¼¥ÈÈÖ¹æ¤ò»È¤Ã¤ÆƱ¤¸³°Éô¥Û¥¹¥È¤ÈÄÌ¿®¤·¤è¤¦¤È¤¹¤ë¤Ê¤é¤Ð¡¢2ÈÖÌܤΥۥ¹¥È¤Ë¤è¤Ã¤Æ»È¤ï¤ì¤ë³°Éô¥Ý¡¼¥ÈÈÖ¹æ¤Ï¥é¥ó¥À¥à¤ËÁª¤Ð¤ì¤ë¡£¤³¤Î¤è¤¦¤ÊNAT¤Ï¡¢»þ¤Ë¤ÏRestricted cone NAT¤Î¤è¤¦¤Ë¸«¤¨¡¢Ê̤λþ¤Ë¤ÏSymmetric NAT¤Î¤è¤¦¤Ë¸«¤¨¤ë¡£

´ØÏ¢µ»½Ñ [ÊÔ½¸]

Connection Trackingµ¡Ç½ [ÊÔ½¸]

NAT¤äNAPT¤Ç¤ÏFTP¤äSIP¤Ê¤É¤ÎVoIP¤Ê¤É¤¦¤Þ¤¯Æ°ºî¤·¤Ê¤¤¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤¬¤¢¤ë¤¿¤á¡¢¤µ¤é¤Ë¥³¥Í¥¯¥·¥ç¥ó¤È¥È¥é¥Ã¥­¥ó¥°¤¹¤ë¤³¤È¤Ç¤½¤ì¤é¤ËÂн褷¤¿µ»½Ñ¡£Linux¤Îiptables¤Ê¤É¤Ç¼ÂÁõ¤µ¤ì¤Æ¤¤¤ë¡£

GapNATµ¡Ç½ [ÊÔ½¸]

½»Í§ÅŹ©À½¤ÎADSL¥â¥Ç¥à¤ËÆ⢤Υ롼¥¿¤Ë¼ÂÁõ¤µ¤ì¤¿DMZ¤ò¼Â¸½¤¹¤ëµ¡Ç½¤Î̾¾Î[1]¡£ 1¤Ä¤Î¥°¥í¡¼¥Ð¥ëIP¥¢¥É¥ì¥¹¤·¤«Ä󶡤µ¤ì¤Ê¤¤IPÀܳ¥µ¡¼¥Ó¥¹´Ä¶­²¼¤Ë¤ª¤¤¤Æ¡¢DHCP¤Ë¤è¤ê¥í¡¼¥«¥ë¤Î°ì¤Ä¤Î¥³¥ó¥Ô¥å¡¼¥¿¤Ë¥°¥í¡¼¥Ð¥ëIP¥¢¥É¥ì¥¹¤ò³ä¤êÅö¤Æ¡¢¤½¤ì°Ê³°¤Î¥³¥ó¥Ô¥å¡¼¥¿¤Ë¤Ï¥í¡¼¥«¥ëIP¥¢¥É¥ì¥¹¤ò³ä¤êÅö¤Æ¤ë¡£¤³¤ì¤Ë¤è¤Ã¤Æ¡¢¥°¥í¡¼¥Ð¥ëIP¥¢¥É¥ì¥¹¤ò³ä¤êÅö¤Æ¤é¤ì¤¿¥³¥ó¥Ô¥å¡¼¥¿¤Ï¡¢¥°¥í¡¼¥Ð¥ëIP¥¢¥É¥ì¥¹¤òľÀÜ»ÈÍѤ·¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¥Í¥Ã¥È¥ï¡¼¥¯¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤òÆ°ºî¤µ¤»¤ë¤³¤È¤¬¤Ç¤­¤ë¡£

UPnP ¤Îµ¬Äꤹ¤ëInternet Gateway Device(IGD) [ÊÔ½¸]

UPnP¤Î¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥²¡¼¥È¥¦¥§¥¤¥Ç¥Ð¥¤¥¹(IGD)»ÅÍͤ˽àµò¤·¤¿NAT¥ë¡¼¥¿¤Ï¡¤¤½¤ì¤ËÂбþ¤·¤¿¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤«¤éÍÍ¡¹¤ÊÁàºî(Action)¤ò¼õ¤±ÉÕ¤±¤ë¤³¤È¤¬²Äǽ¤Ç¤¢¤ë¡£¤³¤ÎÆ°ºî¤ÎÃæ¤Ë¡¢¥Ý¡¼¥È¥Þ¥Ã¥Ô¥ó¥°¤òºîÀ®¡¦ºï½ü¡¦¾ðÊó¼èÆÀ¤ò¹Ô¤¦Áàºî(Action)¤¬¤¢¤ë¡£UPnP NAT Traversal¤È¤â¸Æ¤Ð¤ì¤ë¡£

¤³¤ì¤Ë¤è¤ê¡¢»ÈÍѤ¹¤ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤¬¥Ý¡¼¥È¥Þ¥Ã¥Ô¥ó¥°¤òÍ׵᤹¤ë¾ì¹ç¡¢½¾Íè¤Ï¥æ¡¼¥¶¡¼¤¬NAT¥ë¡¼¥¿¤ËÎ㤨¤Ðweb¥Ö¥é¥¦¥¶¤«¤é¥¢¥¯¥»¥¹¤¹¤ë¤Ê¤É¤·¤Æ¡¢¼êÆ°¤ÇÀßÄê¤ò²Ã¤¨¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤«¤Ã¤¿¤â¤Î¤¬¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¼«¿È¤¬Ä¾Àܥ롼¥¿¡¼¤Ë¥¢¥¯¥»¥¹¤·¥Ý¡¼¥È¥Þ¥Ã¥Ô¥ó¥°¤Î¥¨¥ó¥È¥ê¡¼¤òÄɲᦺï½ü¤Ç¤­¤ë¤è¤¦¤Ë¤Ê¤Ã¤¿¡£

»Ô¾ì¤Ë½Ð²ó¤ë¡Ö¥Ö¥í¡¼¥É¥Ð¥ó¥É¥ë¡¼¥¿¡×¤Ê¤É¤Î¾¦ÉÊ̾¤Î¤â¤Î¤Ç¡ÖUPnPµ¡Ç½ÅëºÜ¡×¤ä¡ÖUPnP NAT TraversalÂбþ¡×¤Ê¤É¤È½ñ¤«¤ì¤Æ¤¤¤ëÀ½Éʤ¬¤³¤ì¤ËÅö¤¿¤ë¡£

IPv4 IPv6´Ö NAT [ÊÔ½¸]

2007¸½ºß¡¢IP¥¢¥É¥ì¥¹¸Ï³éÌäÂê¤Ç­¤ê¤Ê¤¤¤È¤µ¤ì¤Æ¤¤¤ëIPv4¤ÎIP¥¢¥É¥ì¥¹¤Ç¤¢¤ë¤¬¡¢¾­ÍèŪ¤Ë¤ÏIPv6¤ÎIP¥¢¥É¥ì¥¹ÂηϤ˰ܹԤ¹¤ì¤Ð¡¢¸Ï³éÌäÂê¤Ï²ò·è¤¹¤ë¤È¸«¤é¤ì¤Æ¤¤¤ë¡£¤·¤«¤·¡¢¤½¤Î°Ü¹Ô´ü´Ö¤Ë¤ª¤¤¤Æ¤ÏIPv4¤ÈIPv6¤ÎÁÐÊý¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤¬º®ºß¤¹¤ë¤³¤È¤Ë¤Ê¤ê¡¢Î¾¥Í¥Ã¥È¥ï¡¼¥¯¤òÀܳ¤¹¤ëNAT(¥×¥í¥È¥³¥ëÊÑ´¹¤â¹Ô¤¦¤¿¤á¥²¡¼¥È¥¦¥§¥¤¤È¸Æ¤Ö¤Î¤¬ÂÅÅö)¤¬É¬ÍפȤʤ롣¼ÂºÝ¤Î¥²¡¼¥È¥¦¥§¥¤¤Î¼ÂÁõÊýË¡¤¬RFC 2766¤Ë¤è¤Ã¤ÆÄó°Æ¤µ¤ì¤Æ¤¤¤ë¡£

´ØÏ¢¹àÌÜ [ÊÔ½¸]
¥¨¥ó¥É¥Ä¡¼¥¨¥ó¥ÉÀܳÀ­
IP¥¢¥É¥ì¥¹¸Ï³éÌäÂê
NAT traversal
¥é¡¼¥¸¥¹¥±¡¼¥ëNAT

»²¾È [ÊÔ½¸]

1.^ STUN
2.^ NAT Types (PDF).
3.^ Francois Audet, Cullen Jennings (January 2007) (text). RFC 4787 Network Address Translation (NAT) Behavioral Requirements for Unicast UDP. IETF 2007ǯ8·î29Æü±ÜÍ÷¡£.

³°Éô¥ê¥ó¥¯ [ÊÔ½¸]
RFC 1631 - The IP Network Address Translator (NAT)
RFC 2766 - Network Address Translation - Protocol Translation (NAT-PT)
RFC 3022 - Traditional IP Network Address Translator (Traditional NAT)
RFC 3235 - Network Address Translator (NAT)-Friendly Application Design Guidelines
RFC 4787 - Network Address Translation (NAT) Behavioral Requirements for Unicast UDP
Linux¤ÎConnection Trackingµ¡Ç½ÀâÌÀ




¥«¥Æ¥´¥ê¡§¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤Î¥×¥í¥È¥³¥ë

¥³¥ß¥å¥Ë¥Æ¥£¤Ë¤Ä¤Ö¤ä¤­¤òÅê¹Æ

ºÇ¶á¤ÎÅê¹Æ¤¬¤¢¤ê¤Þ¤»¤óµã¤­´é
¤Ä¤Ö¤ä¤­¡¦¥È¥Ô¥Ã¥¯¡¦¥¤¥Ù¥ó¥È¡¦¥¢¥ó¥±¡¼¥È¤òºîÀ®¤·¤Æ»²²Ã¼Ô¤È¸òή¤·¤è¤¦¤ï¡¼¤¤¡Ê´ò¤·¤¤´é¡Ë
»²²Ã¥á¥ó¥Ð¡¼ 3¿Í
³«ÀßÆü
2012ǯ4·î2Æü

4438Æü´Ö±¿±Ä

¥«¥Æ¥´¥ê
PC¡¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È
´ØÏ¢¥ï¡¼¥É
´ØÏ¢¥ï¡¼¥É¤òÅÐÏ¿¤·¤è¤¦

ÊÔ½¸¤«¤é´ØÏ¢¥ï¡¼¥É¤òÅÐÏ¿¤¹¤ë¤È¡¢¥³¥ß¥å¥Ë¥Æ¥£¤¬mixi¥ï¡¼¥É¤Ëɽ¼¨¤µ¤ì¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡ª