Middleboxes
RFC 3234 defines middleboxes as devices on the path between a sender and receiver that do more than basic IP routing.
Middleboxes services
Middleboxes can provide three main types of services:
- address translation (NAT):
- used to support private networks
- modifies IP addresses and port numbers in packet headers
- security services:
- firewalls: block or filter traffic based on packet information, and may send packets for deeper inspection (e.g., deep packet inspection)
- Intrusion Detection Systems (IDS): monitor traffic and detect suspicious patterns, typically generating alerts rather than blocking traffic
- Intrusion Prevention Systems (IPS): actively block or drop traffic identified as malicious
- performance improvements:
- content caching (e.g., proxy caches or CDNs)
- data compression
- load balancing across multiple servers
Middleboxes and layering
For many years, the Internet architecture had a clear separation between:
- the network layer
- routers in the network core forward datagrams based on the IP datagram header
- the transport/application layers
- implemented in hosts operating at the network edge
Middleboxes relax this separation by inspecting and sometimes modifying traffic across multiple layers:
- a NAT box rewrites network-layer IP addresses and transport-layer port numbers
- firewalls and IDS/IPS systems may inspect packet headers at multiple layers (network, transport, and sometimes application) to make forwarding or blocking decisions