Part 9 · 2 chapters · ~12 min

NAT and Firewalls

Network address translation and port mapping, carrier-grade NAT and IP-based rate limiting, NAT and load balancer idle timeouts, keep-alives, stateful and stateless firewalls, security groups and network ACLs, egress control, and peer-to-peer traversal with STUN and TURN.

18

NAT

NAT exists because IPv4 has about four billion addresses for far more devices. IPv6 removes the need, but NAT will be part of most connections for many years.

NAT, AND WHY IDLE CONNECTIONS DIE
many private addresses behind one public one, with a table that forgets
phone 110.0.0.5:51000phone 210.0.0.6:51000NAT gatewaypublic 102.89.1.2NAT table102.89.1.2:40001 ↔ 10.0.0.5:51000serverapi.bank.example:443
swipe the figure sideways, or tap expand for full screen
1/5
translation
A NAT rewrites outgoing packets' private source address and port to its public address and a chosen port, and remembers the mapping in a table so replies can be translated back.
private source → public address and porta table remembers each mapping
19

Firewalls, security groups and egress

controlstatetypical use
stateful firewall / security grouptracks connections; replies allowed automaticallyallow 443 in to load balancers; allow app → DB on 5432
stateless ACL (cloud NACL)each packet judged alone; replies need explicit rulescoarse subnet-level guards
egress allowlistsoutbound restricted to known destinationsstop data exfiltration and SSRF reaching unexpected hosts
Kubernetes NetworkPolicypod-to-pod allow rulesonly transfers pods may reach the ledger

Default deny inbound, least privilege between tiers, and explicit egress for systems handling money or personal data. Cloud Engineering part 2 covers VPC firewalls in detail.