THE UNTOLD STORY: How the PIX Firewall and NAT Saved the Internet

THE UNTOLD STORY: How the PIX Firewall and NAT Saved the Internet

The Serial Port

1 год назад

454,880 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@cal2127
@cal2127 - 28.02.2025 00:26

god internet security would have been a nightmare with the end to end principal intact

Ответить
@TheTechCatalyst
@TheTechCatalyst - 09.02.2025 04:53

This is some really well done internet history! Thanks!

Ответить
@xuser48
@xuser48 - 29.01.2025 21:57

When I shifted from ISDN to ADSL I needed a NAT router that wasn't pricey so I found an old DEC PC, two NIC's and a Linux-based NAT.

Ответить
@mulllhausen
@mulllhausen - 21.01.2025 13:46

NAT was and is a bad idea. It stops the internet from being P2P. IPv6 solved this tho, so that's something at least.

Ответить
@justincase5272
@justincase5272 - 14.01.2025 11:35

I wrote articles in 2000 which pushed NAT into the limelight. I also had a small hand in 1997 in the formation and adoption of IPv6.

Ответить
@eliporter3980
@eliporter3980 - 10.01.2025 17:37

My first IT job in 2004 I was doing help desk and we had a Cisco PIX and I thought it was the coolest thing ever and it was my first time learning about network security. Now I'm a security consultant but I haven't thought about the PIX in years. This was a cool trip down memory lane.

Ответить
@harrycebex6264
@harrycebex6264 - 09.01.2025 22:47

Background music ruins informative tubes.👎

Ответить
@DanielTekmyster
@DanielTekmyster - 03.01.2025 21:49

The pix was my first firewall I learned to configure, and was what I compared others to followed by sourcefire which then once again was acquired by Cisco!

Ответить
@computersales
@computersales - 03.01.2025 12:08

That's pretty cool. I've recycled a lot of these firewalls over the years. It is interesting to know why they are designed the way they are and not using proprietary hardware.

Ответить
@jasonsong86
@jasonsong86 - 03.01.2025 06:36

Legendary and people take for granted.

Ответить
@EVPaddy
@EVPaddy - 03.01.2025 01:33

I built an ISP together with a friend from the early 90ies on. In our business, I think we barely used NAT until we (well, more HE, my friend, but that’s another story) sold in 2000. But where I needed NAT, I just used Linux with masquerading. Never had a PIIX.

Ответить
@JuniorSantiago3x
@JuniorSantiago3x - 02.01.2025 21:24

All i can say is "WOW" this is high-quality

Ответить
@rizwanarasheed
@rizwanarasheed - 02.01.2025 16:20

My first exposure to NAT was in 1997 with a Webramp M3 appliance. It was an impressive little device that had the ability to use 3 dial-up serial port modems via DB9 connectors. I hooked up a small medical office to the internet with the M3. It would provide enough private IP space to allow their 10 or so user devices to get on the internet to do basic tasks such as email and light web browser use. Web sites were simple back then so it worked out rather well.

Ответить
@aaroncoulter3462
@aaroncoulter3462 - 02.01.2025 10:14

That’s pretty telling when the guy that invented NAT agreed with his critics and decided to focus on IPv6 instead.

Ответить
@ralfbaechle
@ralfbaechle - 02.01.2025 00:36

One of the PIX missfeatires was that it did not allow TCP connections with ECN (Enhanced Congestion Notification) TCP feature to be established. I don't know if Cisco was slow to fix.the issue, or POX sites were slow to rill out new firmware - but for a while this was a huge issue where ECN and PIX did collide. Linux (and presumably other OSs) support forums were full of it. To this day this is the first thought when the PIX is mentioned somewhere.

Ответить
@jamesworley2674
@jamesworley2674 - 01.01.2025 22:44

I started my career not long before these came out & still have an HA pair of 535s in my legacy lab.

Ответить
@mprest10
@mprest10 - 01.01.2025 22:34

Loved the PIX firewalls

Ответить
@andrewmaynard6693
@andrewmaynard6693 - 01.01.2025 20:37

SIP ALG in a nutshell

Ответить
@madmadmal
@madmadmal - 01.01.2025 03:54

STUN should have a video with NAT, a very important development.

Ответить
@rolandschweiger8678
@rolandschweiger8678 - 31.12.2024 19:56

and ever since the late 1990s i HATED NAT and always saw it as only a temporary bad workaround. At that time e.g. i used IP-to-IP telephony to my girlfriend living abroad, and one day this no longer worked because i no longer had a proper IP address..... ever since the early 2000s i loved IPv6. It makes thinks so easy, no more NAT, no more distinguishing between private and public ... and easy properly dividing IPv6 addresses into a host and client part. Any we now have 2024 and ipv6 is still being soooooooooooooo slow in implementation. Right up to date THE MAIN PROBLEM for IPv4 + NAT is the reachability from outside. Only with things like port-forwarding is it possible to make devices being reached directly from the internet. With ipv6 any device can have its own proper world-wide unique address, just like in the original concept of the internet, so if it wants, it can always be reached. And i do not understand why we wre still using NAT and so many things on the internet have no ipv6 right up to now. Are people really so lazy?

Ответить
@richardmellish2371
@richardmellish2371 - 30.12.2024 14:43

If you can leave some parts of this video uncontaminated by extraneous and distracting "music" (particularly percussion) why not leave it out altogether?

Ответить
@paulfalke6227
@paulfalke6227 - 30.12.2024 06:54

I saw a Cisco 2500 series router in your cabinet. Long time ago I configured and distributed these boxes. Since then, many things have changed, but some not. Bitter sweet memories.

Ответить
@RKingis
@RKingis - 30.12.2024 03:26

IP masquerading

Ответить
@MachineGunJelly584
@MachineGunJelly584 - 30.12.2024 02:15

I started my networking career by transferring connections from PIX to ASA so this really brought some good memories 😊. And some not so great when remembering how the PIX died just before I had setup all the connections and fw rules to the ASA 😂

Ответить
@MachineGunJelly584
@MachineGunJelly584 - 30.12.2024 01:59

Great video but drop the horrible background music!!

Ответить
@MRooodddvvv
@MRooodddvvv - 29.12.2024 17:51

And as result of it we got abandoning of P2P concept and everything got over centralized and monopolized. Classic example of short sighted solution

Ответить
@autohmae
@autohmae - 29.12.2024 12:50

I think TCP Slow Start might even be a bigger deal, after all NAT greatly reduced IPv6 adoption long term

Ответить
@ericnewton5720
@ericnewton5720 - 29.12.2024 09:01

The irony is, you still have holdouts like me still using ipv4 behind a nat router. Lol

Ответить
@ThreeWishes777
@ThreeWishes777 - 29.12.2024 02:33

Why is the music loud 😭

Ответить
@osterbybruk
@osterbybruk - 27.12.2024 17:44

I'm so hard rn.

Ответить
@bobriemersma
@bobriemersma - 26.12.2024 23:24

I need to go check the basement. My mid-90s first NAT router was a used small form-factor x86 PC running MS-DOS with two Ethernet cards and software by somebody I can't recall. I soon moved to an early SMC Barricade box.

Ответить
@kevinmassey1164
@kevinmassey1164 - 26.12.2024 17:11

I was in my late 20’s in 94 and landed my first job in the industry. It was at an ISP, I had no experience and zero college…I helped customers connect their Win 3.1.1 and Macs to the internet (good ol’ Trumpet).

Dial-up uses could get a /26 for a little extra monthly fee and all T1 or Frame-Relay customers got full Class C blocks….mostly unused of course

Ответить
@ninjasiren
@ninjasiren - 26.12.2024 10:01

Its been a while since I touched my Cisco CCNA thingy, this video is somewhat helpful on trying to refresh it abit haha

Ответить
@hlasrozumu
@hlasrozumu - 16.12.2024 12:59

Decommission IPv4 and use IPv6 instead

Ответить
@hlasrozumu
@hlasrozumu - 16.12.2024 12:58

IPv4 must die

Ответить
@ytdlgandalf
@ytdlgandalf - 07.12.2024 19:16

alternate title, how the PIX and NAT delayed ipv6 indefinitely

Ответить
@mansnilsson4382
@mansnilsson4382 - 09.11.2024 13:21

I respectfully and strongly disagree with the notion "saved". It resulted in the E2E model breaking, and cemented the inequality of servers and clients. It has set back service development of the things we could do on the real Internet in favour of immense effort being spent on accommodating the brokenness of the NAT model.
The proper solution was, is, and will continue to be IPv6. Anything blocking it is rearranging deck chairs.

Ответить
@CoreyThompson73
@CoreyThompson73 - 31.10.2024 23:18

If you've studied the 7 layer OSI model (I first did back in 1990-91), NAT shouldn't seem too revolutionary...I mean, you can swap out layer 3 and 4 and leave 5-7 intact

Ответить
@cgungryfcdjs1352
@cgungryfcdjs1352 - 24.10.2024 12:52

yeah i know this story

Ответить
@cgungryfcdjs1352
@cgungryfcdjs1352 - 24.10.2024 12:51

ipv6

Ответить
@cgungryfcdjs1352
@cgungryfcdjs1352 - 24.10.2024 12:45

well I'm glad the internet got saved lol

Ответить
@servicekid7453
@servicekid7453 - 20.10.2024 22:07

Limiting the growth of the internet wasn’t such a bad idea. Just look at how many complete morons there are on social media. If they were kept off the internet would be a better place 😂

Ответить
@robertsteinbach7325
@robertsteinbach7325 - 18.10.2024 05:15

Oh, you know IPv4 and IPv6. IPv5? The idea was to not use IP addresses at all but to use Routing Labels....like MPLS. The research into IPv5 lead to MPLS.

Ответить
@OptiNationReview
@OptiNationReview - 08.10.2024 09:24

What is the music playing at the end? I love it!

Ответить
@YS_Production
@YS_Production - 06.10.2024 23:44

While PAT is commonly reffered to simply as NAT (which is an umrella term that encompasses PAT among others), It's a bit odd that the whole video is about PAT, yet it's not mentioned even once (or I missed it?)

Ответить
@wfenwick
@wfenwick - 04.10.2024 06:25

The pix snd nat basically killed the proxy firewall which would have been much more secure in the long run since that's what we have all the time anyway now for the most part. If all machines had been addressable to each other, we might have had a much higher software quality and not delegated security to the network layer so the application people could continue to ignore writing quality software resilient to attackers.

Ответить
@waynenocton
@waynenocton - 30.09.2024 15:33

I remember when we first got the nat software, but the name of it escapes me. I work with IPv4 on several networks every single day, and I know it fairly well, but IPv6 is a total mystery to me and I admit I have avoided using it totally.

Ответить
@jamesford7182
@jamesford7182 - 23.09.2024 07:10

Cisco, wow. Haven't thought about them in a few years. If you really wanted to feel humbled around 2000, you took a Cisco Certification test. Those tests were written by a group of autistic sadists. I remember the first one I took vividly. CCNA. I spent three full hours reading multiple choice questions where every answer looked right or every answer looked wrong. I was panicking because I had studied hard and I felt helpless with each question. In the end I was checking out of the test and told the gal running the main desk that I would see her again when I retook the test. She pointed to the pages coming out of a printer and said she didn't think so. I had a score in the area of 950 out of 1000. I couldn't believe it. The people who wrote those tests were some evil demons.

Ответить