Re: [Fwd: I-D ACTION:draft-jennings-midcom-stun-results-00.txt]
Rohan Mahy <[email protected]>
| Newsgroups | gmane.ietf.midcom |
|---|---|
| Message-ID | <[email protected]> |
On Feb 15, 2004, at 4:56 PM, Pyda Srisuresh wrote: > Cullen, > > Interesting compilation of results. Thank you. A few comments below. > > 1. Primary & Secondary columns in the draft being different - This > strikes me > as wierd. Would appreciate if you can shed some light on the test used > to > categorize it thus. If the tests did indeed correctly categrorize a > box as > being different between primary & secondary port users - Does someone > have a > clue as to why a vendor might have chosen to do this intentionally? > (or) is it > likely a unintended bug in the product? who knows the motivation? I suspect its a bug. > Take the case of a Primary being port-restricted and secondary being > symmetric > - Is the primary truely tested for port-restricted NAT criteria with > multiple > outgoing and incoming sessions? I..e, Did the same primary-port > end-point > initiate multiple outgoing connections; yes and yes. the test client has two IP addresses from which it initiates several requests in some cases with the same source port. > And, even as some of the outgoing > connections have aged out, the permitted incoming connections are > restricted to > only those coming from the (ExtAddr, ExtPort) tuples to which there > were > outgoing sessions previously? Likewise, Was a secondary port user > unable to > initiate multiple outgoing sessions using the same port bind? > > In case, the test was performed using a single session on primary port > user, I > believe, the box may as well have been a "Symmetric NAT" all across > (primary as > well as secondary port users). > > Likewise, take the case of primary being port-restricted and secondary > being > full-cone. Depending upon how the test was performed, this may very > well have > been "Full cone" for both primary and secondary port users. > > 2. Group-D/BAD port-binding sounds buggy to me. Why would a vendor > choose to do > this intentionally? I.e., hope this is the right thing to do most of > the time? Exactly! thanks, -rohan