RE: Port preservation

"Christopher A. Martin" <[email protected]> Mon, 26 Apr 2004 15:28:42 -0500
Newsgroups gmane.ietf.midcom
Organization SIP1 Information Services
Message-ID <008501c42bcd$11c94670$6402a8c0@HOME2>
Hi all,
The only reason that I can think of, that may be a good reason, is to
provide the appearance that a client is communicating directly with a
server on a standard server port (for that professional, I'm a big
organization look and feel). Some applications do check for this for
paranoid security reasons, but they are less common.

We typically call this a static port translation, irregardless of
vendor, and it can be configured on many of the popular enterprise class
firewalls.

The other common type of configuration used for the same reason would be
a static IP NAT translation, which provides the server with a whole
range of ports that it can be listening on.

Chris

-----Original Message-----
From: [email protected] [mailto:[email protected]] On Behalf Of
Cullen Jennings
Sent: Monday, April 26, 2004 3:42 PM
To: Yutaka Takeda; Midcom; [email protected]
Subject: Re: [midcom] Port preservation


There may be many but the two reasons I have heard are below - neither
of
which make much sense to me.

Makes debugging easier by not switching the port traffic is on. This
allows
network sniffers and such guess the type of traffic from the port.
(Personally I find this argument a little hard to buy given it is the
source
port that is being preserved and using ports for traffic type
determination
is usually based on the destination port)

Higher odds of interoperability for protocols. The argument goes that A
sends though a NAT to B. B may reply expecting to go to a certain port
number so if that does not change life will be better. I suspect that
most
applications that reply to the correct IP, are likely to also reply to
port
the packet came from but who knows.

The most common answer I get to this questions and the one that seems
most
believable ... "Because vendor X's NAT worked that way so we made ours
do
the same"

I don't know - it is a good questions. Can others provide any insight
into
this?



On 4/23/04 11:19 AM, "Yutaka Takeda" <[email protected]> wrote:

> 
> Does anyone know what the real motivation for NAT designers to
> implement the port preservation[1] is? Is there an actual service
> or application that depends on this behavior? I just realized that
> I know such NATs exist but why...
> 
> [1] 
>
http://www.ietf.org/internet-drafts/draft-jennings-midcom-stun-results-0
0.txt
> 
> Yutaka
> 
> _______________________________________________
> midcom mailing list
> [email protected]
> https://www1.ietf.org/mailman/listinfo/midcom
> 


_______________________________________________
midcom mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/midcom