[173721] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Carrier Grade NAT

daemon@ATHENA.MIT.EDU (Lee Howard)
Fri Aug 1 12:01:49 2014

X-Original-To: nanog@nanog.org
Date: Fri, 01 Aug 2014 12:01:48 -0400
From: Lee Howard <Lee@asgard.org>
To: joshua rayburn <jbrayburn@gmail.com>, Colton Conor <colton.conor@gmail.com>
In-Reply-To: <CAGvVXhRzfXdS3Gc8s-8N4fg49mLPPz7xucCP0zb-6_7sDdLLQg@mail.gmail.com>
Cc: nanog@nanog.org
Errors-To: nanog-bounces@nanog.org



On 7/30/14 3:45 PM, "joshua rayburn" <jbrayburn@gmail.com> wrote:

>
>Starting in 3.10 code you can utilize Bulk Port Allocation to carve out
>small consecutive port bundles for end users as to not mess up SIP
>functionsand High Speed Logging to log individual customers ports for law
>enforcement needs without overrunning your logging server.


http://tools.ietf.org/html/rfc6056 documents a security concern with bulk
port assignments.

Lee



home help back first fref pref prev next nref lref last post