Re: Proposal: UP&P
Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]>
| Newsgroups | gmane.network.freenet.technical |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Mar 12, 2007 at 05:04:44PM +0000, Michael Rogers wrote:
> Matthew Toseland wrote:
> > I was
> > under the impression that the difference between port restricted and
> > symmetric was precisely this - that a symmetric NAT would allocate a
> > new port for every { source port, source IP, dest port, dest IP },
> > whereas a port restricted cone will usually reuse the port, and just
> > ignore packets coming from IPs other than ones we have sent packets to?
>
> That sounds right, but to muddy the waters even further some people have
> abandoned the "full cone/restricted cone/port restricted cone/symmetric"
> terminology because it doesn't cover all possible combinations of
> mapping and filtering behaviour - see tables 6 and 8 of the STUNT paper:
>
> http://nutss.gforge.cis.cornell.edu/pub/imc05-tcpnat.pdf
>
> Roughly speaking, it looks like 70% of NATs can punch UDP holes to each
> other, and some of the 70% can punch holes to some of the remaining 30%.
> This is much worse than I thought - the real world success rate could
> be anywhere between 49% and 91%, depending on the value of "some".
>
> Port prediction works for 94% of NATs after a few retries, but it
> requires out-of-band communication...
Out-of-band communication is possible ... sometimes. :|
>
> Cheers,
> Michael
_______________________________________________
Tech mailing list
[email protected]
http://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFF+YcqA9rUluQ9pFARAmj8AKC/ZEvgqoYqcPrwaCrzJRG8qYEXzwCgsdzp zw9CNGBjtM1hTU1e+ePlQlQ= =NKLf -----END PGP SIGNATURE-----