Re: Clarification required
"Sam K. Sankoorikal" <[email protected]> Sat, 30 Nov 2002 16:42:04 +0530
| Newsgroups | gmane.ietf.nat |
|---|---|
| Organization | Wipro Technologies |
| Message-ID | <[email protected]> |
------=_NextPartTM-000-7a76020b-fe0c-11d6-ba7f-006067005148
Content-Type: multipart/alternative;
boundary="------------020309090401080007020006"
--------------020309090401080007020006
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Hi Rajiv,
??? ??? Good Day!
??? ??? I have gone through section 4.3 of the NAT-MIB . I quote the
section:
" - Setting the natConfStatus to 'active'(1) will enable
nat on the interface. Note that the associated entries in the
natConfAddrMapTable and natConfProtTable (if any) must also
be made active.
- The Address Bind and Address-Port Table will have the entries
created due to this nat configuration. A Management Station may
also, if deemed necessary, create entries Address Bind or a
Address-Port Bind entry and link those entries to the appropriate
address map configured. "
The above section does not tell us the values to be set in case you
needed to create an entry in the natConfAddrMapTable. ie what value
would I have to set natConfAddrMapEntryType to go on and create an entry
NatConfAddrMapEntry ::= SEQUENCE {
natConfAddrMapName SnmpAdminString,
natConfAddrMapIndex Integer32,
natConfAddrMapEntryType INTEGER,
natConfAddrMapDirection INTEGER,
natConfLocalAddrType InetAddressType,
natConfLocalAddrFrom InetAddress,
natConfLocalAddrTo InetAddress,
natConfLocalPortFrom Integer32,
natConfLocalPortTo Integer32,
natConfGlobalAddrType InetAddressType,
natConfGlobalAddrFrom InetAddress,
natConfGlobalAddrTo InetAddress,
natConfGlobalPortFrom Integer32,
natConfGlobalPortTo Integer32,
natConfProtocol BITS,
natConfAddrMapStorageType StorageType,
natConfAddrMapStatus RowStatus
}
natConfAddrMapEntryType OBJECT-TYPE
SYNTAX INTEGER {
static (1),
dynamic (2)
}
MAX-ACCESS read-create
STATUS current
DESCRIPTION
"This config parameter can be used to set up static
or dynamic address maps."
::= { natConfAddrMapEntry 3 }
I also quote Rohits' input:
Static Address assignment
?? In the case of static address assignment, there is one-to-one address
?? mapping for hosts between a private network address and an external
?? network address for the lifetime of NAT operation.? Static address
?? assignment ensures that NAT does not have to administer address
?? management with session flows.
Dynamic Address assignment
?? In this case, external addresses are assigned to private network
?? hosts or vice versa, dynamically based on usage requirements and
?? session flow determined heuristically by NAT. When the last session
?? using an address binding is terminated, NAT would free the binding so
?? that the global address could be recycled for later use. The exact
?? nature of address assignment is specific to individual NAT
?? imp
lementations.?
(The functionality has been described. More could be added on how we would configure the same)
Based on the above definition of dynamic NAT it seems that the
NatConfAddrMapEntry 's? which are dynamic are created on the fly, on a
need basis by the NAT module/protocol and can't be exactly specified as
dynamic and created by a user through SNMP. However if we wanted to
configure a Static NAT entry then that configuration could be created by
the user by specifying other [Direction, Addresses, Ports, protocols]
OID value other than the natConfAddrMapEntryType. This value will be
derived. Hence I think it would be clearer if the
natConfAddrMapEntryType were given a max access of read-only. This is
something which cannot be specified by the user. To tell more about the
dynamic entries I think by enabling NAT on an interface and running a
network application using NAT, then dynamic NAT entries would be
created. The same could be repeated for NAPT.
natConfAddrMapEntryType OBJECT-TYPE
SYNTAX INTEGER {
static (1),
dynamic (2)
}
MAX-ACCESS *read-only*
Thanks and Regards,
Sam.
--
? Sam K. Sankoorikal.
??Home Net Solutions <http://www.wipro.com/homenet> ,
? Wipro Technologies <http://www.wipro.com>
? Ganapa Complex,
? #53/1 Hosur Rd Madivala,
? Bangalore, India 560068
? PBX:???? +91 80 5502001 extn 3114
? [email protected]
--------------020309090401080007020006
Content-Type: multipart/related;
boundary="------------010401040506090504070105"
--------------010401040506090504070105
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html;charset=us-ascii">
<title></title>
</head>
<body>
<meta http-equiv="Content-Type" content="text/html;charset=ISO-8859-1">
<title></title>
Hi Rajiv,<br>
<br>
Good Day!<br>
<br>
I have gone through section 4.3 of the NAT-MIB . I quote the section:<br>
<br>
<pre wrap="">" - Setting the natConfStatus to 'active'(1) will enable<br> nat on the interface. Note that the associated entries in the<br> natConfAddrMapTable and natConfProtTable (if any) must also<br> be made active.<br><br> - The Address Bind and Address-Port Table will have the entries <br> created due to this nat configuration. A Management Station may<br> also, if deemed necessary, create entries Address Bind or a <br> Address-Port Bind entry and link those entries to the appropriate<br> address map configured. "<br><br><br></pre>
The above section does not tell us the values to be set in case you needed
to create an entry in the natConfAddrMapTable. ie what value would I have
to set natConfAddrMapEntryType to go on and create an entry<br>
<br>
<pre wrap="">NatConfAddrMapEntry ::= SEQUENCE {<br> natConfAddrMapName SnmpAdminString,<br> natConfAddrMapIndex Integer32,<br> natConfAddrMapEntryType INTEGER,<br> natConfAddrMapDirection INTEGER,<br> natConfLocalAddrType InetAddressType,<br> natConfLocalAddrFrom InetAddress,<br> natConfLocalAddrTo InetAddress,<br> natConfLocalPortFrom Integer32,<br> natConfLocalPortTo Integer32,<br> natConfGlobalAddrType InetAddressType,<br> natConfGlobalAddrFrom InetAddress,<br> natConfGlobalAddrTo InetAddress,<br> natConfGlobalPortFrom Integer32,<br> natConfGlobalPortTo Integer32,<br> natConfProtocol BITS,<br> natConfAddrMapStorageType StorageType,<br> natConfAddrMapStatus RowStatus<br>}</pre>
<pre wrap="">natConfAddrMapEntryType OBJECT-TYPE<br> SYNTAX INTEGER {<br> static (1),<br> dynamic (2)<br> }<br> MAX-ACCESS read-create<br> STATUS current<br> DESCRIPTION<br> "This config parameter can be used to set up static <br> or dynamic address maps."<br> ::= { natConfAddrMapEntry 3 }</pre>
<pre wrap=""><br>I also quote Rohits' input:<br><br><span
class="598050803-30112002">Static Address assignment<br><br> In the case of static address assignment, there is one-to-one address<br> mapping for hosts between a private network address and an external<br> network address for the lifetime of NAT operation. Static address<br> assignment ensures that NAT does not have to administer address<br> management with session flows.<br><br>Dynamic Address assignment<br><br> In this case, external addresses are assigned to private network<br> hosts or vice versa, dynamically based on usage requirements and<br> session flow determined heuristically by NAT. When the last session<br> using an address binding is terminated, NAT would free the binding so<br> that the global address could be recycled for later use. The exact<br> nature of address assignment is specific to individual NAT<br> imp
<br>lementations.</span> <br><br>(The functionality has been described. More could be added on how we would configure the same)<br></pre>
Based on the above definition of dynamic NAT it seems that the NatConfAddrMapEntry
's which are dynamic are created on the fly, on a need basis by the NAT module/protocol
and can't be exactly specified as dynamic and created by a user through SNMP.
However if we wanted to configure a Static NAT entry then that configuration
could be created by the user by specifying other [Direction, Addresses, Ports,
protocols] OID value other than the natConfAddrMapEntryType. This value will
be derived. Hence I think it would be clearer if the natConfAddrMapEntryType
were given a max access of read-only. This is something which cannot be specified
by the user. To tell more about the dynamic entries I think by enabling NAT
on an interface and running a network application using NAT, then dynamic
NAT entries would be created. The same could be repeated for NAPT.<br>
<br>
<pre wrap="">natConfAddrMapEntryType OBJECT-TYPE<br> SYNTAX INTEGER {<br> static (1),<br> dynamic (2)<br> }<br> MAX-ACCESS <b>read-only</b><br><br><br>Thanks and Regards,<br>Sam.<br><br></pre>
<br>
<div class="moz-signature">-- <br>
<title>signature</title>
<meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">
<table cellpadding="2" cellspacing="2" border="1" width="20%">
<tbody>
<tr>
<td valign="top"><img
src="cid:[email protected]" alt=" " width="104"
height="114" align="left">
</td>
<td valign="top" width="80%" bgcolor="#ccffff" nowrap="true">
Sam K. Sankoorikal.<br>
<a href="http://www.wipro.com/homenet">Home Net Solutions</a> ,<br>
<a href="http://www.wipro.com">Wipro Technologies</a><br>
Ganapa Complex,<br>
#53/1 Hosur Rd Madivala,<br>
Bangalore, India 560068<br>
PBX: +91 80 5502001 extn 3114<br>
<a class="moz-txt-link-abbreviated"
href="mailto:[email protected]">[email protected]</a><br>
</td>
</tr>
</tbody>
</table>
<br>
</div>
<br>
<br>
</body>
</html>
--------------010401040506090504070105
Content-Type: image/jpeg
Content-ID: <[email protected]>
Content-Transfer-Encoding: base64
/9j/4AAQSkZJRgABAQAAAQABAAD/2wBDAAgGBgcGBQgHBwcJCQgKDBQNDAsLDBkSEw8UHRof
Hh0aHBwgJC4nICIsIxwcKDcpLDAxNDQ0Hyc5PTgyPC4zNDL/2wBDAQkJCQwLDBgNDRgyIRwh
MjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjL/wAAR
CAByAGgDASIAAhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAA
AgEDAwIEAwUFBAQAAAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkK
FhcYGRolJicoKSo0NTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWG
h4iJipKTlJWWl5iZmqKjpKWmp6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl
5ufo6erx8vP09fb3+Pn6/8QAHwEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREA
AgECBAQDBAcFBAQAAQJ3AAECAxEEBSExBhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYk
NOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOE
hYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk
5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD3DFHp6UZ70UAFA+mKKytS8QWOlRiWdnaP
zfKd4l3eW2M4bHSplJRV2xSkoq7NX/PFR3FxDa273FxKsUMa7nkY4Cj1Ncnqvj3To7SePTZh
Ld4GzcpUEEcsD7V5+mrao0MmhPMZbGcAqhX5twbccHvknmuWrjIQ0WuhhPEJO0df8z1KHxIk
niybRvLAjRAFl3cmTGSuPTBrdV1bcFYEqcHB6GvM9Cguba782dt92CsocnO4gEVKb6cX32wS
GMBg8secZKknOfzH/wCqvHhn8edw5b69Ox3YfDVKiV+p6QevNHevPdJ8eQnVdTuNQuVS1EYe
KFTuOc4CqO5wea6Pw54rtvEj3CW1pcQiHBLSAbSD05HQ+1e9TrRna3U1q4KtSTlJaK2vqb/4
0Gj/AAo9ua2OQKKDRQAf5FFFHTpQBXvbyGwspruckRQqXYgZOPpXjviXVtO1LVTd2SzQNcgG
aOUABnHGQQcHjFd54w8SXWjN9lOnwT2txEQHlfO49CCo/wA815Jd+W0JVpRG45U9wfWvOxVT
mlyHm4yopSVMs+fCZYkywZjlG7cdj79sVBqGtw2OJrdg06MoADdQcg8+nf8ACsGGW4upHiYQ
+VnLPG5Jfpg45wQe/wBafdjT7e1WeXMSDOCECliO2CMdQP8AJxXO8PDmUZarsdWGw/KuZnT6
V47iW6sUuUkEMXmJK6jOVJ+Q9MniqEnioSwCMuyklnCn+EZOP0rz+fWrVh+5hmODwjvwOmTk
fSq8VwZpCY5Rvfna2cLx2OK1p5ThoS5oxs/+H/zPWoY2dF3Wp6AXztVcZYE8nG0eprp9F8ZX
ej28dpZCxhNxMGaa5yd2RgFjn5RwfWvPrO8llcxTnLsny5O1cAdCe3rx1rURWklXyo3llxgM
BwfcnnnI7Z6Yr3MDgY255ammOzCeJ02ij6WjJaJSzIxIBJXofp7UvpXmngnxrrEl3BpmtG3l
jbgXbvsYHnAOeGz26H616Z265rOpTlTdpHmKSlsHWijr9aKzGFISACT2HPelPH1pkwkaF1ic
JKVOxiuQDjgkUAeY+MfEOla55cNvbzPPbsfLuCdoIP3hjqRwPTpXDXdjG0bOibcLkusigL+B
HJ9q6/W9J1ePWjdapbx+dcPtEsC/u5MD25zj15qLUtLgXTHhMIdnVgQzEbseuPzr5rF4/wBj
XSlu/l+pyUMPUrVHN/lY421jjt7RnzHtUb96gKP8Oa5O6eXVL9pvNZhksFZsjknn8jXTX900
NjsAJWRSfmzgdskfjXOWS7/nY9tuD1x7+terhYNc1SW7PUUPhi+pXl0hbggv8pGehpIdNitS
WQEyAY+bnn+lasrGFioxu6k+lQAF3AHLMf1r2KNByXNMxquCdolYFgpGdmD09TXomlx20OkQ
XUxUl0DYY8Zx6frXBGMPG2AucE5I+6fU+tdNBczPYW8TgoEjC7On5114SLjOUXscGLm1C0ep
tWGqIus2huooJrQSqJI/ILqwOB93qcdvp+Fe7ggqCDxjjivB/CsN7N4gtzp9na3VzH+8RLo4
QY756gj1HNe7xlzGpkChiAWCnIB789xWWOfvIMGrJjjRRmiuE7AGfTmj60f56UfSgDmPEcs9
xcpbMDHbRnzNx/iYDrn0Gen+Fcpq15bW1sXUpI6glV6A9sZ6j+VeoOiSLtdQ6jsRnmvEfFXn
Xeu6hNbRz3FtCzHzBFhFUcHBAxjpXzmMyl1MV7ec7p9P66HrZYqc5NS0S6nEasG+1SMzYVjn
KDA9ePx5rKgUxTM4B2/w56iulvLANF510OUxhAf/ANfcgVizWsjq0wj2IOPlP3RxX0mDoTlB
NLRHLjlFVWqeyIdxkYHDFmPock1aS0MZ3XGUAONmMs3tj8DzRY2d1eSYtkkaXsRxn15JFaX9
nPbXCLLswqFSoOevr69/SvVhGTPJq1Yx0uUkt0ublFjB8lBzn65xn8a1aAqoMKoA9hV/SNOX
VdSjszeW9s8nEbThirN2Xj1rdRUFqzinNzaRreE/D0mqanaTSLdi1LkC6s3Aa3lAyN3dQenT
nP1r2xFZY0VmLkAAsRgk+vFY+jeFNJ0K4e5sbd45pE2OfNdhjrwCfWtqvJr1vaSutj0aFN04
2e4H6UUUVgbBR39arXupWOmxLLf31vaRs21XuJVjBb0BYjmm2WqadqW/7Bf2l3s+/wDZ51k2
56Z2k4oAt+wrn/GltNc+FrtYHRSmJX3kgFV5I478CtxbmB7iS3SeNp4wGeNWG5QehI6jOD1r
OvL7QtTjn0m41KykM2YJLdbpQ5J4K4ByD7daFbqCbWqPntJZbqVVlJYKx4MfAbPQ89fYdvWl
37i8UW6WVYy5OMnoMZyO2c59PrXq+reG/DmsDSdP0rV9Ms7e2lcmKCZHkctj7vJy3HU5rZl0
jwtZadc6RbzadZzG2a2JaVBKqnn5snPU55r0frcFFKKCUnZ2PLNNiMGkwGGIvNLhEjBJLZPQ
e/4dqyZm813Y8ZbdjPTmvU/C2gaZot7FNc67p10bddtqqSqME/xkE9cHAA6ZqSXwVocVlqdt
e3ttFNeTNPbTllV4E/hAyeQDnPY1p9cglynmvDVJS5+p59ZeG728fTcGOOLUd628zH5d67vk
PoTt/wA816H4Y8AafBptvPrOnrJqQcyHdIWEeDwBg4PQH61u6PFo+kaLZaal9ZypaoArNInL
Dq3Xgkkn8a2UdJIw6OrqejKcg1yVcTKWkdEdVPDxjq9R3vR160ySSOJC8rqid2ZgB+tNiube
4z5E8UuOvluGx+Vcp0Epoo/nRQBU1PTLPWdOn0+/gSa2nQo6Oobj1GehHUH1FfNngq9uPhr8
Wm0u+bbbvN9iuC2QCjEbJO3H3Tn0Jr6e/wA8V4t8bvA19q1/putaNZTXN1IRaXCQoS2f+Wb8
dAOQT24oA5fQPEWpeEPjhf8A9uyMWvbpra8bJC7XYGNwP7o+Uj/Zrttc0ax8TfHbTraC0hRN
Ht1u7+aNADJJu3IrEdeq9fesH4ueA9UfStC1mGOe/wBSito7PUGgjLNIyrkSYHPXIJ/3a7n4
S6BqOnaBc6vrgmOs6tL5s5nGJAijCA5/E/iKAPIPFMEUPx9ZIIUiQ6pAQsa4GTtJOPUnn6mu
g/aJtoYtY0S5jhiSaaGYSSKoDPtK4ye+M8VmeNrG/wBN+N76rLpt7JaJeQXIkhgZwyALkjHX
ofyrY+OsE2uf8I7qml29xdWUsEoWWOFjgllwCMZBPofQ0AQ+LNG8DaV8JrFBHZxeIZLWCWLy
zm4d2ALFh12kbuo9MVkanp+op8ArS41mBjKuqqLBp1PmRwMhyATyFJBIHTGK9g8AWfh/UvDV
heJpdq2pQwRQXck9kFmWVUUEEsufTBHFZ3xws7q9+HQS0tpZ2jvYnZYlLFVCuM4HbJA/GgDh
fBGh+Bx8J7jUfEqWSXNxJOI5ppNsvyjCiPv154B5NW/gTPqdhp+uX919oGhRQ+Yu/OwyLkts
zxnA5x7UfD/wvoXjD4d3Ghaha+XrtuZWilliZJIVJyhViOV3E5H1rM+GuuXXhW91Twp4qgu4
NIug8LyPG2y2k5BOcYCtnr64NAC+DoLz4xeN7268SXUr6ZaR+b9ijlKoMnCIB2Hcnqce9avx
R8E2XgfT7PxN4Te40qeGdYpRBM2CDkhhk+owRnBB6VmeFU1X4O+M7qPWNOubjR7tPK+22sRc
FQco4/PlTzz376PxK8YD4g2lp4b8I2N9fFpxLPKIGVcgEBefrkk4HAoA9M+Hfiabxd4Ks9Uu
VAustDPtGAXU4JA9wQfxoqTwB4Yfwh4MstJmdXuV3S3DIfl8xjkgH0HA/CigDpx1AArjrPxg
954zjsYtv9lSCe3ik8pgZJ4grFg/3ShHmKAMklCeldfgEEEZGOaozaPZSadDYx28UMdspFrs
jGLc7CgZB0BCsQPrQBztv8QI20eXULnTLi3J0+fUrVCwbz4I2wDxypO5Dgj+LjOKkufF0/kx
2q2RtdY+12lvJbTMHCiUbyQynn5Ekx0OQMip18DaNF4ebR7eERJJBFbTzhQZZYkIJQk9A2Dx
0G44rUg0DTLOJVs7KGBo5TPE+zcVlKFN/J5ODjntxQBl23jix1GO3/s0yt58trGHaPKh5vm8
s4PDqgJb+7kZ9Kjg+IGlSWzXbQ3sNs1m97FI8Q/exK4QkAEnqy4zjIOfWtLS/DWm6Zp1laLC
s7WjtMs0gG9pnDB5Djjc25vpnAqDV/COn6josmnWyR2O62SzWWOPcRArBvK6j5Tgjgg89aAJ
NJ1yTxHZ3zWUMtpNDM1sJLlVdTIAMkbWwwGfWuetPE+vDQodXlks7pbvUFsrWCG3ZXkU3Gzf
ncckxq7Y6D1wK6vQtMk0fS0spL2S6KOxV3ULtUnIQAdh0GSTUkWkadBbWVtFZwpDYuJLWMDi
JgGAK++GYfiaAMibxtp8dmZltb15FFw0sCRgvGtuxSVmOcYDcDBOe2asp4r0qYPsaV1Fxb2o
IiOHkmVWQD/gLgn0FPn8KaFc20VtLpsRhiEiqqsy/K7bnU4PzKzckHINSN4b0d9SGoGxj+1i
VZhJk4EirsD7c7cheOnQCgDA1L4hWKWWpiwgmmuLazluYTLH+6kKP5Y755kwoGMntVx/GNtb
xCJNNvXu/t0djJbRxKG8xoxJnk8gIS3rxg4qvoPgWPS4Lm1vbw39pcMkjwvFtDyrL5vmsck5
LYO0ccVtXPhzS7olntyrtd/bfMjkZG84rsLZB7r8uOmKANX3ooNFAAOlA5UUUUAA6D6UYHpR
RQAH7p+lH8R+lFFAC0n8R+lFFAA3Q/SkHb6UUUAKOp+tIO30oooAX+I0UUUAf//Z
--------------010401040506090504070105--
--------------020309090401080007020006--
------=_NextPartTM-000-7a76020b-fe0c-11d6-ba7f-006067005148--