Part 9 · 2 chapters · ~12 min
NAT and Firewalls
Network address translation and port mapping, carrier-grade NAT and IP-based rate limiting, NAT and load balancer idle timeouts, keep-alives, stateful and stateless firewalls, security groups and network ACLs, egress control, and peer-to-peer traversal with STUN and TURN.
18
NAT
NAT exists because IPv4 has about four billion addresses for far more devices. IPv6 removes the need, but NAT will be part of most connections for many years.
NAT, AND WHY IDLE CONNECTIONS DIE
many private addresses behind one public one, with a table that forgets
swipe the figure sideways, or tap expand for full screen
1/5
translation
A NAT rewrites outgoing packets' private source address and port to its public address and a chosen port, and remembers the mapping in a table so replies can be translated back.
private source → public address and porta table remembers each mapping
19
Firewalls, security groups and egress
| control | state | typical use |
|---|---|---|
| stateful firewall / security group | tracks connections; replies allowed automatically | allow 443 in to load balancers; allow app → DB on 5432 |
| stateless ACL (cloud NACL) | each packet judged alone; replies need explicit rules | coarse subnet-level guards |
| egress allowlists | outbound restricted to known destinations | stop data exfiltration and SSRF reaching unexpected hosts |
| Kubernetes NetworkPolicy | pod-to-pod allow rules | only transfers pods may reach the ledger |
Default deny inbound, least privilege between tiers, and explicit egress for systems handling money or personal data. Cloud Engineering part 2 covers VPC firewalls in detail.