Re: RE: [MBONED] FW: WGLC: draft-ietf-behave-multicast-06.txt

Marshall Eubanks <[email protected]> Wed, 6 Jun 2007 12:55:39 -0400
Newsgroups gmane.ietf.magma,gmane.ietf.nat.behave
Message-ID <[email protected]>
On Jun 6, 2007, at 12:49 PM, Brian Haberman wrote:

>
>
> Marshall Eubanks wrote:
>> Hello;
>>
>> On 6/6/07, Brian Haberman <[email protected]> wrote:
>>>
>>>
>>> Alvaro Fernandez wrote:
>>>> Brian:
>>>>
>>>>
>>>>
>>>> My e-mail was not an answer to Albert, sorry for that,
>>>>
>>>>
>>>>
>>>> It is an idea regarding the BEHAVE Internet Draft and how the  
>>>> multicast
>>>> NAPT can allow outside multicast routers to uniquely identify  
>>>> different
>>>> multicast SSM channels (S,G) coming from inside interfaces in  
>>>> the case
>>>> two inside interfaces use the same multicast group.
>>>>
>>>
>>> How prevalent do people expect the scenario of a SSM sender being
>>> located behind a NAPT?
>>>
>>
>> I would expect that this has the potential of being fairly common.
>>
>> - Enterprises use NATs a lot. (I am not going to get into the  
>> question
>> as to whether they should...)
>>
>> - Enterprises use multicast video
>>
>> - This video needs to go to remote offices, which are commonly behind
>> their own NATs.
>
> I assume you mean without utilizing a VPN connection?

Yes, could be.

Or could be using NAT through a VPN connection. I have seen this too.  
I have seen large company mergers
where they have extreme RFC 1918 collisions between the old pieces  
and use NATs everywhere.

>
>>
>> If that multicast moves to SSM then they will need NAT traversal.
>>
>>
>>>>
>>>>
>>>> In the BEHAVE draft, REQ-4, if there is a host on the inside  
>>>> interface
>>>> sending UDP packets to a multicast group, the NAPT can change the
>>> source
>>>> address and the port but not the multicast group address. In this
>>> way, I
>>>> think the outside routers can not differentiate the two channels
>>> because
>>>> they have the same source (the public interface) and the same  
>>>> multicast
>>>> group address.
>>>>
>>>
>>> Is it possible for the NAPT to have multiple external addresses  
>>> to use
>>> as source addresses?
>>>
>>
>> Why would it need this ? ASM - (*,G) : SSM (S,G) ?
>> Or are you worried about 2 different SSM sources using the same G.
>>
>
> Yes, that is the scenario Alvaro described.  Two senders using the  
> same
> G both behind the same NAPT.
>

This has to be supported IMHO.


> Regards,
> Brian

Regards
Marshall

>
> _______________________________________________
> MBONED mailing list
> [email protected]
> https://www1.ietf.org/mailman/listinfo/mboned