TCP through NATs and Firewalls

Saikat Guha <[email protected]> Tue, 17 May 2005 18:34:57 -0400
Newsgroups gmane.ietf.midcom
Message-ID <[email protected]>
Hi,

We recently studied the current state of TCP traversal through NATs and
firewalls. The results are available at:
     http://nutss.gforge.cis.cornell.edu/pub/draft-imc-stunt.pdf


Abstract:
In recent years, the standards community has developed
techniques for traversing NAT/firewall boxes with UDP
(that is, establishing UDP flows between hosts behind
NATs). Because of the asymmetric nature of TCP connection
establishment, however, NAT traversal of TCP
is more difficult. Researchers have recently proposed a
variety of promising approaches for TCP NAT traversal.
The success of these approaches, however, depend
on how NAT boxes respond to various sequences of TCP
(and ICMP) packets. This paper presents the first broad
study of NAT behavior for a comprehensive set of TCP
NAT traversal techniques over a wide range of commercial
NAT products. We developed a publicly available
software test suite that measures the NAT's responses
both to a variety of isolated probes and to complete TCP
connection establishments. We test sixteen NAT products
in the lab, and 75 home NATs in the wild. Using
these results, as well as market data for NAT products,
we estimate the likelihood of successful NAT traversal
for home networks. The insights gained from this paper
can be used to guide both design of TCP NAT traversal
protocols and the standardization of NAT/firewall behavior,
including the IPv4-IPv6 translating NATs critical for
IPv6 transition.

-- 
Saikat

_______________________________________________
midcom mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/midcom
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)

iD8DBQBCinGRnFltqi691/oRAuIbAJ0T3wZXXbHeWepoAO43rMkBdEE4gACfbGjG
4C0/b7rma861IzsJFdaznWs=
=GTpg
-----END PGP SIGNATURE-----