
From nobody Fri May  2 08:33:24 2014
Return-Path: <spencerdawkins.ietf@gmail.com>
X-Original-To: behave@ietfa.amsl.com
Delivered-To: behave@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BF9991A0976 for <behave@ietfa.amsl.com>; Thu,  1 May 2014 13:25:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.1
X-Spam-Level: 
X-Spam-Status: No, score=-0.1 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9fdPtQ4QCkLu for <behave@ietfa.amsl.com>; Thu,  1 May 2014 13:25:53 -0700 (PDT)
Received: from mail-ob0-x230.google.com (mail-ob0-x230.google.com [IPv6:2607:f8b0:4003:c01::230]) by ietfa.amsl.com (Postfix) with ESMTP id 2769E1A0956 for <behave@ietf.org>; Thu,  1 May 2014 13:25:53 -0700 (PDT)
Received: by mail-ob0-f176.google.com with SMTP id wp4so4173996obc.35 for <behave@ietf.org>; Thu, 01 May 2014 13:25:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :content-type; bh=NU6dOhW7FemRm6I9T9eqIFq47k4TOcG3YTOcSRZJRMk=; b=hbkRgkf5IRXvcK5lJxcwCUtByppJK3siJeMB8PkFz21gnZxSbQ82pddlxdyzMJVmt9 4oZcMSSEJj7zlL9iUrvDKimmW3Pc6EalPDw3PeDVhP82wD5PtVSTKaKyysc3zkJGA496 QMQfwUmCpsaZbBR82lIcq1wDJC5Xm5dgJd1wyoCVXYUv6Ffh7VpyMmPMl8QX+bjs58qa qA3FFPFu8VCehtFkoQRVZgrhjWwRe3QBmoqiKm/NMJLM7Mf+IoT74xu+agX48vjkKo0c 8qvrX9ibmRuVRAH3056ZkgyryOAwVFYUQgxuCynU95in0xmy73ABqzhquKaLW/iTYlYa jrzQ==
X-Received: by 10.60.125.72 with SMTP id mo8mr13111173oeb.36.1398975951077; Thu, 01 May 2014 13:25:51 -0700 (PDT)
Received: from [192.168.0.13] (cpe-76-187-7-89.tx.res.rr.com. [76.187.7.89]) by mx.google.com with ESMTPSA id w4sm36848363oem.8.2014.05.01.13.25.48 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 01 May 2014 13:25:50 -0700 (PDT)
Message-ID: <5362ADCB.4050802@gmail.com>
Date: Thu, 01 May 2014 15:25:47 -0500
From: Spencer Dawkins <spencerdawkins.ietf@gmail.com>
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:24.0) Gecko/20100101 Thunderbird/24.4.0
MIME-Version: 1.0
To: draft-ietf-behave-ipfix-nat-logging@tools.ietf.org
Content-Type: multipart/alternative; boundary="------------070305050403020606040406"
Archived-At: http://mailarchive.ietf.org/arch/msg/behave/IICMnBJnXq9CV8-yJNb6TJkmIao
X-Mailman-Approved-At: Fri, 02 May 2014 08:33:22 -0700
Cc: behave@ietf.org
Subject: [BEHAVE] AD Evaluation of draft-ietf-behave-ipfix-nat-logging-03
X-BeenThere: behave@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: mailing list of BEHAVE IETF WG <behave.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/behave>, <mailto:behave-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/behave/>
List-Post: <mailto:behave@ietf.org>
List-Help: <mailto:behave-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 May 2014 20:25:59 -0000

This is a multi-part message in MIME format.
--------------070305050403020606040406
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Dear draft-ietf-behave-ipfix-nat-logging Authors,

I've completed my AD evaluation for this draft. I found some things I'd 
like to see changed before proceeding, but most are editorial. Please 
take a look, and let me know what you think.

My notes follow ... you should be able to find my questions and comments 
by searching for "SD:".

Thanks,

Spencer

In the Abstract

    NAT devices are required to log events like creation and deletion of
                    ^^^^^^^^
SD: Is this required, like, legally required, or ? Is it more like 
"Operators need NAT devices to log events ..."?

    translations and information about the resources it is managing.  The
    logs are required in many cases to identify an attacker or a host
    that was used to launch malicious attacks and/or for various other
    purposes of accounting.  Since there is no standard way of logging
    this information, different NAT devices behave differently and hence
                                ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
SD: Is this "different NAT devices log this information differently"?

    it is difficult to expect a consistent behavior.  The lack of a
    consistent way makes it difficult to write the collector applications
    that would receive this data and process it to present useful
    information.  This document describes the information that is
    required to be logged by the NAT devices.
    ^^^^^^^^^^^^^^^^^^^^^^^^
SD: Same as previous question - is this "logged by"?

2.  Introduction

    The IPFIX Protocol [RFC5101bis] defines a generic push mechanism for
    exporting information and events.  The IPFIX Information Model
    [IPFIX-IANA] defines a set of standard Information Elements (IEs)
    which can be carried by the IPFIX protocol.  This document details
    the IPFIX Information Elements(IEs) that are required for logging by
    a NAT device.  The document will specify the format of the IE's that
    are required to be logged by the NAT device and all the optional
        ^^^^^^^^^^^^^^^^^^^^^
SD: Now that we're in the document body, if this is required, shouldn't 
there be a reference to where the requirements are stated?

    fields.  The fields specified in this document are gleaned from
    [RFC4787] and [RFC5382].

    Test [3GPP]
    ^^^^^^^^^^^
SD: Is something missing here? It's just the word "Test" and a reference.

    This document and [I-D.behave-syslog-nat-logging] are provided in
    order to standardize the events and parameters to be recorded, using
    IPFIX [RFC5101bis] and SYSLOG [RFC5424]respectively.

3.  Scope

    This document provides the information model to be used for logging
    the NAT devices including Carrier Grade NAT (CGN) events.  This
                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
SD: This sentence seems somewhat turned around - "logging events", not 
"logging the NAT devices".

    document focuses exclusively on the specification of IPFIX IE's.
    This document does not provide guidance on the transport protocol
    like TCP, UDP or SCTP that is to be used to log NAT events. The log
    events SHOULD NOT be lost but the choice of the actual transport
    protocol is beyond the scope of this document.

SD: I'm not understanding why this last sentence is needed, especially 
with a normative requirement for what you do when you are doing 
something outside the scope of the document ...

    The existing IANA IPFIX IEs registry [IPFIX-IANA] already has
    assignments for many NAT logging events.  For convenience, this
    document uses those same IEs.  However, as stated earlier, this
    document is not defining IPFIX or NetFlow v9 as the framework for
    logging.  Rather, the information contained in these elements is

SD: I got lost on "these elements" - is that "the elements in the 
existing registry"

    within the scope of this document.

    This document assumes that the NAT device will use the existing IPFIX
    framework to send the log events to the collector.  This would mean
    that the NAT device will specify the template that it is going to use
    for each of the events.  The templates can be of varying length and
    there could be multiple templates that a NAT device could use to log
    the events.

    The implementation details of the collector application is beyond the
    scope of this document.

    The optimization of logging the NAT events are left to the
                                               ^^^
    implementation and are beyond the scope of this document.
                       ^^^
SD: It's a nit, but those "are"s should be "is"s.

4.  Applicability

    NAT logging based on IPFIX uses binary encoding and hence is very
    efficient.  IPFIX based logging is recommended for environments where
    a high volume of logging is required, for example, where per-flow
    logging is needed.  However, IPFIX based logging requires a collector
    that processes the binary data and requires a network management
    application that converts this binary data to a human readable
    format.

5.  Event based logging

    An event in a NAT device can be viewed as a happening as it relates
                                                ^^^^^^^^^
SD: Is this "a state transition"? I found "a happening" somewhat odd.

    to the management of NAT resources.  The creation and deletion of NAT
    sessions and bindings are examples of events as it results in the
    resources (addresses and ports) being allocated or freed.  The events
    can happen either through the processing of data packets flowing
    through the NAT device or through an external entity installing
    policies on the NAT router or as a result of an asynchronous event
    like a timer.  The list of events are provided in Section 4.1. Each
    of these events SHOULD be logged, unless they are administratively
    prohibited.  A NAT device MAY log these events to multiple collectors
    if redundancy is required.  The network administrator will specify
    the collectors to which the log records are to be sent.

    A collector may receive NAT events from multiple CGN devices and
    should be able to distinguish between the devices.  Each CGN device
    ^^^^^^
SD: I'm not sure why this isn't a SHOULD, or even a MUST.

    should have a unique source ID to identify themselves.  The source ID
    ^^^^^^
SD: Again, I'm not sure why this isn't a SHOULD, or even a MUST.

    is part of the IPFIX template and data exchange.

    Prior to logging any events, the NAT device MUST send the template of
    the record to the collector to advertise the format of the data
    record that it is using to send the events.  The templates can be
    exchanged as frequently as required given the reliability of the
    connection.  There SHOULD be a configurable timer for controlling the
    template refresh.  NAT device SHOULD combine as many events as
    possible in a single packet to effectively utilize the network
    bandwidth.

5.1.  Logging of destination information

    Logging of destination information in a NAT event has been discussed
    in [RFC6302] and [RFC6888].  Logging of destination information
    increases the size of each record and increases the need for storage
    considerably.  It increases the number of log events generated
    because when the same user connects to a different destination, it
    results in a log record per destination address.  Logging of
    destination information also results in the loss of privacy and hence
    should be done with caution.  However, this draft provides the
    necessary fields to log the destination information in cases where
    they are required to be logged.

5.2.  Information Elements

    The templates could contain a subset of the Information Elements(IEs)
    shown in Table 1 depending upon the event being logged.  For example
    a NAT44 session creation template record will contain,
                                             ^^^^
SD: Is this the only possible NAT44 template? If so, fine, but if not, 
perhaps "could contain", or "typically contains"?

    {sourceIPv4Adress, postNATSourceIPv4Address, destinationIpv4Address,
    postNATDestinationIPv4Address, sourceTransportPort,
    postNAPTSourceTransportPort, destinationTransportPort,
    postNAPTDestTransportPort, internalAddressRealm, natEvent, timeStamp}

    An example of the actual event data record is shown below - in a
    readable form

    {192.168.16.1, 201.1.1.100, 207.85.231.104, 207.85.231.104, 14800,
    1024, 80, 80, 0, 1, 09:20:10:789}

    A single NAT device could be exporting multiple templates and the
    collector should support receiving multiple templates from the same
    source.observationTimeMilliseconds

    The following is the table of all the IE's that a CGN device would
    need to export the events.  The formats of the IE's and the IPFIX IDs
    are listed below.

SD: I noticed that some IEs below have a name that matches 
http://www.iana.org/assignments/ipfix/ipfix.xhtml#ipfix-information-elements 
for the same IPFIX ID number, but others do not ("timeStamp" here 
doesn't match "observationTimeMilliseconds", but both are IPFIX ID 323, 
aren't they?) Is there a reason to use names that don't match the IANA 
registry?

+----------------------------------+--------+-------+---------------+
    |            Field Name            |   Size |  IANA | Description  |
    |                                  | (bits) | IPFIX |               |
    |                                  |        |    ID |               |
+----------------------------------+--------+-------+---------------+
    |            timeStamp             |     64 |   323 |  System Time  |
    |                                  |        |       |    when the   |
    |                                  |        |       | event     |
    |                                  |        |       | occured.   |
    |          natInstanceId           |     32 |   TBD |  NAT Instance |
    |                                  |        |       | Identifier  |
    |              vlanID              |     16 |    58 |   VLAN ID in  |
    |                                  |        |       |    case of    |
    |                                  |        |       | overlapping  |
    |                                  |        |       | networks   |
    |           ingressVRFID           |     32 |   234 |   VRF ID in   |
    |                                  |        |       |    case of    |
    |                                  |        |       | overlapping  |
    |                                  |        |       | networks   |
    |        sourceIPv4Address         |     32 |     8 |  Source IPv4  |
    |                                  |        |       | Address    |
    |     postNATSourceIPv4Address     |     32 |   225 | Translated  |
    |                                  |        |       |  Source IPv4  |
    |                                  |        |       | Address    |
    |        protocolIdentifier        |      8 |     4 | Transport   |
    |                                  |        |       | protocol   |
    |       sourceTransportPort        |     16 |     7 |  Source Port  |
    |   postNAPTsourceTransportPort    |     16 |   227 | Translated  |
    |                                  |        |       |  Source port  |
    |      destinationIPv4Address      |     32 |    12 | Destination  |
    |                                  |        |       |  IPv4 Address |
    |  postNATDestinationIPv4Address   |     32 |   226 | Translated  |
    |                                  |        |       | IPv4     |
    |                                  |        |       | destination  |
    |                                  |        |       | address    |
    |     destinationTransportPort     |     16 |    11 | Destination  |
    |                                  |        |       | port     |
    | postNAPTdestinationTransportPort |     16 |   228 | Translated  |
    |                                  |        |       | Destination  |
    |                                  |        |       | port     |
    |        sourceIPv6Address         |     27 |   128 |  Source IPv6  |
    |                                  |        |       | address    |
    |      destinationIPv6Address      |    128 |    28 | Destination  |
    |                                  |        |       |  IPv6 address |
    |     postNATSourceIPv6Address     |    128 |   281 | Translated  |
    |                                  |        |       |  source IPv6  |
    |                                  |        |       | addresss   |
    |  postNATDestinationIPv6Address   |    128 |   282 | Translated  |
    |                                  |        |       | Destination  |
    |                                  |        |       |  IPv6 address |
    |       internalAddressRealm       |      8 |   229 | Source    |
    |                                  |        |       | Address Realm |
    |       externalAddressRealm       |      8 |   TBD | Destination  |
    |                                  |        |       | Address Realm |
    |             natEvent             |      8 |   230 | Type of Event |
    |          portRangeStart          |     16 |   361 | Allocated   |
    |                                  |        |       |   port block  |
    |                                  |        |       | start     |
    |           portRangeEnd           |     16 |   362 | Allocated   |
    |                                  |        |       |   Port block  |
    |                                  |        |       | end      |
    |            natPoolID             |     32 |   283 |    NAT pool   |
    |                                  |        |       | Identifier  |
    |          natLimitEvent           |     32 |   TBD |  Limit event  |
    |                                  |        |       | identifier  |
+----------------------------------+--------+-------+---------------+

                       Table 1: Template format Table

5.3.  Definition of NAT Events

    The following are the list of NAT events and the proposed event
    values.  The list can be expanded in the future as necessary. The
    data record will have the corresponding natEvent value to identify
    the event that is being logged.

                    +--------------------------+--------+
                    |        Event Name        | Values |
                    +--------------------------+--------+
                    |   NAT44 Session create   |      1 |
                    |   NAT44 Session delete   |      2 |
                    | NAT Addresses exhausted  |      3 |
                    |   NAT64 Session create   |      4 |
                    |   NAT64 Session delete   |      5 |
                    |     NAT44 BIB create     |      6 |
                    |     NAT44 BIB delete     |      7 |
                    |     NAT64 BIB create     |      8 |
                    |     NAT64 BIB delete     |      9 |
                    |   NAT ports exhausted    |     10 |
                    |      Quota exceeded      |     11 |
                    |  Address binding create  |     12 |
                    |  Address binding delete  |     13 |
                    |  Port block allocation   |     14 |
                    | Port block de-allocation |     15 |
                    |    Threshold reached     |     16 |
                    +--------------------------+--------+

                         Table 2: NAT Event ID table

5.4.  Quota exceeded Event types

    The following table shows the sub event types for the Quota exceeded
    or limits reached event.  The events that can be reported are the
    Maximum session entries limit reached, Maximum BIB entries limit
    reached, Maximum session/BIB entries per user limit reached and
    maximum subscribers or hosts limit reached.

             +---------------------------------------+--------+
             |       Quota Exceeded Event Name       | Values |
             +---------------------------------------+--------+
             |        Maximum Session entries        |      1 |
             |          Maximum BIB entries          |      2 |
             |        Maximum entries per user       |      3 |
             |  Maximum active hosts or subscribers  |      4 |
             |  Maximum fragments pending reassembly |      5 |
             +---------------------------------------+--------+

                     Table 3: Quota Exceeded event table

5.5.  Threshold reached Event types

    The following table shows the sub event types for the threshold
    reached event.  The administrator can configure the thresholds and
    whenever the threshold is reached or exceeded, the corresponding
    events are generated.

    The address pool high threshold event will be reported when the
    address pool reaches a high water mark as defined by the operator.
    This will sever as an indication that the operator might have to add
    more addresses to the pool or an indication that the subsequent users
    may be denied NAT translation mappings.

    The address and port mapping high threshold event is generated, when
    the number of ports in the configured address pool has reached a
    configured threshold.

    The per-user address and port mapping high threshold is generated
    when a single user uses more address and port mapping than a
    configured threshold.

+---------------------------------------------------------+--------+
    |              Threshold Exceeded Event Name              | Values |
+---------------------------------------------------------+--------+
    |            Address pool high threshold event |      1 |
    |             Address pool low threshold event |      2 |
    |      Address and port mapping high threshold event |      3 |
    |  Address and port mapping per user high threshold event |      4 |
    |       Global Address mapping high threshold event |      5 |
+---------------------------------------------------------+--------+

                       Table 4: Threshold event table

5.6.  Templates for NAT Events

    The following is the template of events that will have to logged.
^^^^^^^^^^^^^^^^^^^

SD: I think this is a nit, but the sentence is garbled. "will be logged"?

    The events below are identified at the time of this writing but the
    events are expandable.  Depending on the implementation and
    ^^^^^^^^^^^^^^^^^^^^^
SD: this is a nit, but "set of events is extensible", I think.

    configuration various IE's specified can be included or ignored.

5.6.1.  NAT44 create and delete session events

    These events will be generated when a NAT44 session is created or
    deleted.  The template will be the same, the natEvent will indicate
    whether it is a create or a delete event.  The following is a
    template of the event.

    The destination address and port information is optional as required
    by [RFC6888].  However, when the destination information is
    suppressed, the session log event contains the same information as
    the BIB event.  In such cases, the NAT device SHOULD NOT send both
    BIB and session events.

+----------------------------------+-------------+-----------+
       |            Field Name            | Size (bits) | Mandatory |
+----------------------------------+-------------+-----------+
       |            timeStamp             |          64 |    Yes |
       |          natInstanceID           |          32 |     No |
       |       vlanID/ingressVRFID        |          32 |     No |
       |        sourceIPv4Address         |          32 |    Yes |
       |     postNATSourceIPv4Address     |          32 |    Yes |
       |        protocolIdentifier        |           8 |    Yes |
       |       sourceTransportPort        |          16 |    Yes |
       |   postNAPTsourceTransportPort    |          16 |    Yes |
       |      destinationIPv4Address      |          32 |     No |
       |  postNATDestinationIPv4Address   |          32 |     No |
       |     destinationTransportPort     |          16 |     No |
       | postNAPTdestinationTransportPort |          16 |     No |
       |       internalAddressRealm       |           8 |     No |
       |       externalAddressRealm       |           8 |     No |
       |             natEvent             |           8 |    Yes |
+----------------------------------+-------------+-----------+

                Table 5: NAT44 Session delete/create template

5.6.2.  NAT64 create and delete session events

    These events will be generated when a NAT64 session is created or
    deleted.  The following is a template of the event.

+----------------------------------+-------------+-----------+
       |            Field Name            | Size (bits) | Mandatory |
+----------------------------------+-------------+-----------+
       |            timeStamp             |          64 |    Yes |
       |          natInstanceID           |          32 |     No |
       |       vlanID/ingressVRFID        |          32 |     No |
       |        sourceIPv6Address         |         128 |    Yes |
       |     postNATSourceIPv4Address     |          32 |    Yes |
       |        protocolIdentifier        |           8 |    Yes |
       |       sourceTransportPort        |          16 |    Yes |
       |   postNAPTsourceTransportPort    |          16 |    Yes |
       |      destinationIPv6Address      |         128 |     No |
       |  postNATDestinationIPv4Address   |          32 |     No |
       |     destinationTransportPort     |          16 |     No |
       | postNAPTdestinationTransportPort |          16 |     No |
       |       internalAddressRealm       |           8 |     No |
       |       externalAddressRealm       |           8 |     No |
       |             natEvent             |           8 |    Yes |
+----------------------------------+-------------+-----------+

             Table 6: NAT64 session create/delete event template

5.6.3.  NAT44 BIB create and delete events

    These events will be generated when a NAT44 Bind entry is created or
    deleted.  The following is a template of the event.

          +-----------------------------+-------------+-----------+
          |          Field Name         | Size (bits) | Mandatory |
          +-----------------------------+-------------+-----------+
          |          timeStamp          |          64 |    Yes    |
          |        natInstanceID        |          32 |     No    |
          |     vlanID/ingressVRFID     |          32 |     No    |
          |      sourceIPv4Address      |          32 |    Yes    |
          |   postNATSourceIPv4Address  |          32 |    Yes    |
          |      protocolIdentifier     |           8 |     No    |
          |     sourceTransportPort     |          16 |     No    |
          | postNAPTsourceTransportPort |          16 |     No    |
          |     internalAddressRealm    |           8 |     No    |
          |     externalAddressRealm    |           8 |     No    |
          |           natEvent          |           8 |    Yes    |
          +-----------------------------+-------------+-----------+

               Table 7: NAT44 BIB create/delete event template

5.6.4.  NAT64 BIB create and delete events

    These events will be generated when a NAT64 Bind entry is created or
    deleted.  The following is a template of the event.

          +-----------------------------+-------------+-----------+
          |          Field Name         | Size (bits) | Mandatory |
          +-----------------------------+-------------+-----------+
          |          timeStamp          |          64 |    Yes    |
          |        natInstanceID        |          32 |     No    |
          |     vlanID/ingressVRFID     |          32 |     No    |
          |      sourceIPv6Address      |         128 |    Yes    |
          |   postNATSourceIPv4Address  |          32 |    Yes    |
          |      protocolIdentifier     |           8 |     No    |
          |     sourceTransportPort     |          16 |     No    |
          | postNAPTsourceTransportPort |          16 |     No    |
          |     internalAddressRealm    |           8 |     No    |
          |     externalAddressRealm    |           8 |     No    |
          |           natEvent          |           8 |    Yes    |
          +-----------------------------+-------------+-----------+

               Table 8: NAT64 BIB create/delete event template

5.6.5.  Addresses Exhausted event

    This event will be generated when a NAT device runs out of global
    IPv4 addresses in a given pool of addresses.  Typically, this event
    would mean that the NAT device wont be able to create any new
                                   ^^^^
SD: "won't"

    translations until some addresses/ports are freed.  This event SHOULD
    be rate limited as many packets hitting the device at the same time
    will trigger a burst of addresses exhausted events.

    The following is a template of the event.  Note that either the NAT
    pool name or the nat pool identifier should be logged, but not both.

SD: I lack understanding, but I didn't see anything that looked like a 
NAT pool name in the template. Did I miss something?

                 +---------------+-------------+-----------+
                 |   Field Name  | Size (bits) | Mandatory |
                 +---------------+-------------+-----------+
                 |   timeStamp   |          64 |    Yes    |
                 | natInstanceID |          32 |     No    |
                 |    natEvent   |           8 |    Yes    |
                 |   natPoolID   |          32 |    Yes    |
                 +---------------+-------------+-----------+

                  Table 9: Address Exhausted event template

5.6.6.  Ports Exhausted event

    This event will be generated when a NAT device runs out of ports for
    a global IPv4 address.  Port exhaustion shall be reported per
    protocol (UDP, TCP etc).  This event SHOULD be rate limited as many
    packets hitting the device at the same time will trigger a burst of
    port exhausted events.

    The following is a template of the event.

           +--------------------------+-------------+-----------+
           |        Field Name        | Size (bits) | Mandatory |
           +--------------------------+-------------+-----------+
           |        timeStamp         |          64 |    Yes    |
           |      natInstanceID       |          32 |     No    |
           |         natEvent         |           8 |    Yes    |
           | postNATSourceIPv4Address |          32 |    Yes    |
           |    protocolIdentifier    |           8 |    Yes    |
           +--------------------------+-------------+-----------+

                  Table 10: Ports Exhausted event template

5.6.7.  Quota exceeded events

    This event will be generated when a NAT device cannot allocate
    resources as a result of an administratively defined policy. The
    quota exceeded event templates are described below
                                                      ^
SD: missing period

5.6.7.1.  Maximum session entries exceeded

    The maximum session entries exceeded is generated when the
    administratively configured limit is reached.  The following is the
    template of the event.

                +-----------------+-------------+-----------+
                |    Field Name   | Size (bits) | Mandatory |
                +-----------------+-------------+-----------+
                |    timeStamp    |          64 |    Yes    |
                |  natInstanceID  |          32 |     No    |
                |     natEvent    |           8 |    Yes    |
                |  natLimitEvent  |          32 |    Yes    |
                | configuredLimit |          32 |    Yes    |
                +-----------------+-------------+-----------+

              Table 11: Session Entries Exceeded event template

5.6.7.2.  Maximum BIB entries exceeded

    The maximum BIB entries exceeded is generated when the
    administratively configured limit is reached.  The following is the
    template of the event.

                +-----------------+-------------+-----------+
                |    Field Name   | Size (bits) | Mandatory |
                +-----------------+-------------+-----------+
                |    timeStamp    |          64 |    Yes    |
                |  natInstanceID  |          32 |     No    |
                |     natEvent    |           8 |    Yes    |
                |  natLimitEvent  |          32 |    Yes    |
                | configuredLimit |          32 |    Yes    |
                +-----------------+-------------+-----------+

                Table 12: BIB Entries Exceeded event template

5.6.7.3.  Maximum entries per user exceeded

    This event is generated when a single user reaches the
    administratively configured limit.  The following is the template of
    the event.

            +---------------------+-------------+---------------+
            |      Field Name     | Size (bits) |   Mandatory   |
            +---------------------+-------------+---------------+
            |      timeStamp      |          64 |      Yes      |
            |    natInstanceID    |          32 |       No      |
            |       natEvent      |           8 |      Yes      |
            |    natLimitEvent    |          32 |      Yes      |
            |   configuredLimit   |          32 |      Yes      |
            | vlanID/ingressVRFID |          32 |       No      |
            |  sourceIPv4 address |          32 | Yes for NAT44 |
            |  sourceIPv6 address |         128 | Yes for NAT64 |
            +---------------------+-------------+---------------+

             Table 13: Per-user Entries Exceeded event template

5.6.7.4.  Maximum active host or subscribers exceeded

    This event is generated when the number of allowed hosts or
    subscribers reaches the administratively configured limit.  The
    following is the template of the event.

                +-----------------+-------------+-----------+
                |    Field Name   | Size (bits) | Mandatory |
                +-----------------+-------------+-----------+
                |    timeStamp    |          64 |    Yes    |
                |  natInstanceID  |          32 |     No    |
                |     natEvent    |           8 |    Yes    |
                |  natLimitEvent  |          32 |    Yes    |
                | configuredLimit |          32 |    Yes    |
                +-----------------+-------------+-----------+

         Table 14: Maximum hosts/subscribers Exceeded event template

5.6.7.5.  Maximum fragments pending reassembly exceeded

    This event is generated when the number of fragments pending
    reassembly reaches the administratively configured limit.  The
    following is the template of the event.

           +----------------------+-------------+---------------+
           |      Field Name      | Size (bits) |   Mandatory   |
           +----------------------+-------------+---------------+
           |      timeStamp       |          64 |      Yes      |
           |    natInstanceID     |          32 |       No      |
           |       natEvent       |           8 |      Yes      |
           |    natLimitEvent     |          32 |      Yes      |
           |   configuredLimit    |          32 |      Yes      |
           | internalAddressRealm |           8 |      Yes      |
           | vlanID/ingressVRFID  |          32 |       No      |
           |  sourceIPv4 address  |          32 | Yes for NAT44 |
           |  sourceIPv6 address  |         128 | Yes for NAT64 |
           +----------------------+-------------+---------------+

        Table 15: Maximum fragments pending reassembly Exceeded event
                                  template

5.6.8.  Threshold reached events

    This event will be generated when a NAT device reaches a operator
    configured threshold when allocating resources.  The threshold
    reached events are described in the section above.  The following is
    a template of the individual events.

5.6.8.1.  Address pool high or low threshold reached

    This event is generated when the high or low threshold is reached for
    the address pool.  The template is the same for both high and low
    threshold events

               +-------------------+-------------+-----------+
               |     Field Name    | Size (bits) | Mandatory |
               +-------------------+-------------+-----------+
               |     timeStamp     |          64 |    Yes    |
               |   natInstanceID   |          32 |     No    |
               |      natEvent     |           8 |    Yes    |
               | natThresholdEvent |          32 |    Yes    |
               |     natPoolID     |          32 |    Yes    |
               |  configuredLimit  |          32 |    Yes    |
               +-------------------+-------------+-----------+

      Table 16: Address pool high/low threshold reached event template

5.6.8.2.  Address and port high threshold reached

    This event is generated when the high threshold is reached for the
    address pool and ports.

               +-------------------+-------------+-----------+
               |     Field Name    | Size (bits) | Mandatory |
               +-------------------+-------------+-----------+
               |     timeStamp     |          64 |    Yes    |
               |   natInstanceID   |          32 |     No    |
               |      natEvent     |           8 |    Yes    |
               | natThresholdEvent |          32 |    Yes    |
               |  configuredLimit  |          32 |    Yes    |
               +-------------------+-------------+-----------+

        Table 17: Address port high threshold reached event template

5.6.8.3.  Per-user Address and port high threshold reached

    This event is generated when the high threshold is reached for the
    per-user address pool and ports.

            +---------------------+-------------+---------------+
            |      Field Name     | Size (bits) |   Mandatory   |
            +---------------------+-------------+---------------+
            |      timeStamp      |          64 |      Yes      |
            |    natInstanceID    |          32 |       No      |
            |       natEvent      |           8 |      Yes      |
            |  natThresholdEvent  |          32 |      Yes      |
            |   configuredLimit   |          32 |      Yes      |
            | vlanID/ingressVRFID |          32 |       No      |
            |  sourceIPv4 address |          32 | Yes for NAT44 |
            |  sourceIPv6 address |         128 | Yes for NAT64 |
            +---------------------+-------------+---------------+

    Table 18: Per-user Address port high threshold reached event template

5.6.8.4.  Global Address mapping high threshold reached

    This event is generated when the high is reached for the per-user
    address pool and ports.  This is generated only by NAT devices that
    use a address pooling behavior of paired.

              +---------------------+-------------+-----------+
              |      Field Name     | Size (bits) | Mandatory |
              +---------------------+-------------+-----------+
              |      timeStamp      |          64 |    Yes    |
              |    natInstanceID    |          32 |     No    |
              |       natEvent      |           8 |    Yes    |
              |  natThresholdEvent  |          32 |    Yes    |
              |   configuredLimit   |          32 |    Yes    |
              | vlanID/ingressVRFID |          32 |     No    |
              +---------------------+-------------+-----------+

        Table 19: Global Address mapping high threshold reached event
                                  template

5.6.9.  Address binding create and delete events

    These events will be generated when a NAT device binds a local
    address with a global address and when the global address is freed.
    This binding event happens when the first packet of the first flow
    from a host in the private realm.

+--------------------------------+-------------+---------------+
      |           Field Name           | Size (bits) | Mandatory   |
+--------------------------------+-------------+---------------+
      |           timeStamp            |          64 | Yes      |
      |         natInstanceID          |          32 | No      |
      |            natEvent            |           8 | Yes      |
      |       sourceIPv4 address       |          32 | Yes for NAT44 |
      |       sourceIPv6 address       |         128 | Yes for NAT64 |
      | Translated Source IPv4 Address |          32 | Yes      |
+--------------------------------+-------------+---------------+

                   Table 20: NAT Address Binding template

5.6.10.  Port block allocation and de-allocation

    This event will be generated when a NAT device allocates/de-allocates
    ports in a bulk fashion, as opposed to allocating a port on a per
    flow basis.

    portRangeStart represents the starting value of the range.

    portRangeEnd represents the ending value of the range.

    NAT devices would do this in order to reduce logs and potentially to
    limit the number of connections a subscriber is allowed to use.  In
    the following Port Block allocation template, the portRangeStart and
    portRangeEnd must be specified.


Sivakumar & Penno        Expires August 15, 2014 [Page 17]

Internet-Draft          IPFIX IEs for NAT logging February 2014

    It is up to the implementation to choose to consolidate log records
    in case two consecutive port ranges for the same user are allocated
    or freed.

+--------------------------------+-------------+---------------+
      |           Field Name           | Size (bits) | Mandatory   |
+--------------------------------+-------------+---------------+
      |           timeStamp            |          64 | Yes      |
      |         natInstanceID          |          32 | No      |
      |            natEvent            |           8 | Yes      |
      |       sourceIPv4 address       |          32 | Yes for NAT44 |
      |       sourceIPv6 address       |         128 | Yes for NAT64 |
      | Translated Source IPv4 Address |          32 | Yes      |
      |         portRangeStart         |          16 | Yes      |
      |          portRangeEnd          |          16 | No      |
+--------------------------------+-------------+---------------+

             Table 21: NAT Port Block Allocation event template

6.  Encoding

6.1.  IPFIX

    This document uses IPFIX as the encoding mechanism to describe the
    logging of NAT events.  However, the information that should be
    logged SHOULD be the same irrespective of what kind of encoding
    scheme is used.  IPFIX is chosen because is it an IETF standard that
    meets all the needs for a reliable logging mechanism.  IPFIX provides
    the flexibility to the logging device to define the data sets that it
    is logging.  The IEs specified for logging MUST be the same
    irrespective of the encoding mechanism used.

7.  Acknowledgements

    Thanks to Dan Wing, Selvi Shanmugam, Mohamed Boucadir, Jacni Qin
    Ramji Vaithianathan, Simon Perreault, Jean-Francois Tremblay, Paul
    Aitken and Julia Renouard for their review and comments.

8.  IANA Considerations

    The following information elements are requested from IANA IPFIX
    registry.

    natInstanceId

    externalAddressRealm

    natLimitEvent

9.  Management Considerations

    This section considers requirements for management of the log system
    to support logging of the events described above.  It first covers
    requirements applicable to log management in general.  Any additional
    standardization required to fullfil these requirements is out of
    scope of the present document.  Some management considerations is
    covered in [I-D.behave-syslog-nat-logging].  This document covers the
    additional considerations.

9.1.  Ability to collect events from multiple NAT devices

    An IPFIX collector should be able to collect events from multiple NAT
    devices and be able to decipher events based on the sourceID in the
    IPFIX header.

9.2.  Ability to suppress events

    The exhaustion events can be overwhelming during traffic bursts and
    hence should be handled by the NAT devices to rate limit them before
    sending them to the collectors.  For eg. when the port exhaustion
    happens during bursty conditions, instead of sending a port
    exhaustion event for every packet, the exhaustion events should be
    rate limited by the NAT device.

10.  Security Considerations

    None.

11.  References

11.1.  Normative References

    [RFC2119]  Bradner, S., "Key words for use in RFCs to Indicate
               Requirement Levels", BCP 14, RFC 2119, March 1997.

    [RFC2663]  Srisuresh, P. and M. Holdrege, "IP Network Address
               Translator (NAT) Terminology and Considerations", RFC
               2663, August 1999.

    [RFC4787]  Audet, F. and C. Jennings, "Network Address Translation
               (NAT) Behavioral Requirements for Unicast UDP", BCP 127,
               RFC 4787, January 2007.

    [RFC5382]  Guha, S., Biswas, K., Ford, B., Sivakumar, S., and P.
               Srisuresh, "NAT Behavioral Requirements for TCP", BCP 142,
               RFC 5382, October 2008.

    [RFC6146]  Bagnulo, M., Matthews, P., and I. van Beijnum, "Stateful
               NAT64: Network Address and Protocol Translation from IPv6
               Clients to IPv4 Servers", RFC 6146, April 2011.

    [RFC6302]  Durand, A., Gashinsky, I., Lee, D., and S. Sheppard,
               "Logging Recommendations for Internet-Facing Servers", BCP
               162, RFC 6302, June 2011.

    [RFC6888]  Perreault, S., Yamagata, I., Miyakawa, S., Nakagawa, A.,
               and H. Ashida, "Common Requirements for Carrier-Grade NATs
               (CGNs)", BCP 127, RFC 6888, April 2013.

11.2.  Informative References

    [I-D.ietf-behave-syslog-nat-logging]
               Chen, Z., Zhou, C., Tsou, T., and T. Taylor, "Syslog
               Format for NAT Logging", draft-ietf-behave-syslog-nat-
               logging-06 (work in progress), January 2014.

    [IPFIX-IANA]
               IANA, "IPFIX Information Elements registry",
               <http://www.iana.org/assignments/ipfix>.

    [RFC5101bis]
               Claise, B. and B. Trammel, "Specification of the IP Flow
               Information eXport (IPFIX) Protocol for the Exchange of
               Flow Information", July 2013.

    [RFC5102bis]
               Claise, B. and B. Trammel, "Information Model for IP Flow
               Information eXport (IPFIX)", February 2013.

    [RFC5470]  Sadasivan, G., Brownlee, N., Claise, B., and J. Quittek,
               "Architecture for IP Flow Information Export", RFC 5470,
               March 2009.

Authors' Addresses

    Senthil Sivakumar
    Cisco Systems
    7100-8 Kit Creek Road
    Research Triangle Park, North Carolina  27709
    USA

    Phone: +1 919 392 5158

    Renaldo Penno
    Cisco Systems
    170 W Tasman Drive
    San Jose, California  95035
    USA

    Email: repenno@cisco.com






















Sivakumar & Penno        Expires August 15, 2014 [Page 21]

--------------070305050403020606040406
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <font face="Courier New, Courier, monospace">Dear
      draft-ietf-behave-ipfix-nat-logging Authors,<br>
      <br>
      I've completed my AD evaluation for this draft. I found some
      things I'd like to see changed before proceeding, but most are
      editorial. Please take a look, and let me know what you think.<br>
      <br>
      My notes follow ... you should be able to find my questions and
      comments by searching for "SD:".<br>
      <br>
      Thanks,<br>
      <br>
      Spencer<br>
      <br>
      In the Abstract<br>
      <br>
      &nbsp;&nbsp; NAT devices are required to log events like creation and
      deletion of<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^<br>
      SD: Is this required, like, legally required, or ? Is it more like
      "Operators need NAT devices to log events ..."?<br>
      <br>
      &nbsp;&nbsp; translations and information about the resources it is
      managing.&nbsp; The<br>
      &nbsp;&nbsp; logs are required in many cases to identify an attacker or a
      host<br>
      &nbsp;&nbsp; that was used to launch malicious attacks and/or for various
      other<br>
      &nbsp;&nbsp; purposes of accounting.&nbsp; Since there is no standard way of
      logging<br>
      &nbsp;&nbsp; this information, different NAT devices behave differently and
      hence<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^<br>
      SD: Is this "different NAT devices log this information
      differently"? <br>
      <br>
      &nbsp;&nbsp; it is difficult to expect a consistent behavior.&nbsp; The lack of a<br>
      &nbsp;&nbsp; consistent way makes it difficult to write the collector
      applications<br>
      &nbsp;&nbsp; that would receive this data and process it to present useful<br>
      &nbsp;&nbsp; information.&nbsp; This document describes the information that is<br>
      &nbsp;&nbsp; required to be logged by the NAT devices.<br>
      &nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^^^^ <br>
      SD: Same as previous question - is this "logged by"?<br>
      <br>
      2.&nbsp; Introduction<br>
      <br>
      &nbsp;&nbsp; The IPFIX Protocol [RFC5101bis] defines a generic push
      mechanism for<br>
      &nbsp;&nbsp; exporting information and events.&nbsp; The IPFIX Information Model<br>
      &nbsp;&nbsp; [IPFIX-IANA] defines a set of standard Information Elements
      (IEs)<br>
      &nbsp;&nbsp; which can be carried by the IPFIX protocol.&nbsp; This document
      details<br>
      &nbsp;&nbsp; the IPFIX Information Elements(IEs) that are required for
      logging by<br>
      &nbsp;&nbsp; a NAT device.&nbsp; The document will specify the format of the IE's
      that<br>
      &nbsp;&nbsp; are required to be logged by the NAT device and all the
      optional<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^<br>
      SD: Now that we're in the document body, if this is required,
      shouldn't there be a reference to where the requirements are
      stated?<br>
      <br>
      &nbsp;&nbsp; fields.&nbsp; The fields specified in this document are gleaned from<br>
      &nbsp;&nbsp; [RFC4787] and [RFC5382].<br>
      <br>
      &nbsp;&nbsp; Test [3GPP]<br>
      &nbsp;&nbsp; ^^^^^^^^^^^<br>
      SD: Is something missing here? It's just the word "Test" and a
      reference.<br>
      <br>
      &nbsp;&nbsp; This document and [I-D.behave-syslog-nat-logging] are provided
      in<br>
      &nbsp;&nbsp; order to standardize the events and parameters to be recorded,
      using<br>
      &nbsp;&nbsp; IPFIX [RFC5101bis] and SYSLOG [RFC5424]respectively.<br>
      <br>
      3.&nbsp; Scope<br>
      <br>
      &nbsp;&nbsp; This document provides the information model to be used for
      logging<br>
      &nbsp;&nbsp; the NAT devices including Carrier Grade NAT (CGN) events.&nbsp; This<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^<br>
      SD: This sentence seems somewhat turned around - "logging events",
      not "logging the NAT devices".<br>
      <br>
      &nbsp;&nbsp; document focuses exclusively on the specification of IPFIX
      IE's.<br>
      &nbsp;&nbsp; This document does not provide guidance on the transport
      protocol<br>
      &nbsp;&nbsp; like TCP, UDP or SCTP that is to be used to log NAT events.&nbsp;
      The log<br>
      &nbsp;&nbsp; events SHOULD NOT be lost but the choice of the actual
      transport<br>
      &nbsp;&nbsp; protocol is beyond the scope of this document.<br>
      <br>
      SD: I'm not understanding why this last sentence is needed,
      especially with a normative requirement for what you do when you
      are doing something outside the scope of the document ...<br>
      <br>
      &nbsp;&nbsp; The existing IANA IPFIX IEs registry [IPFIX-IANA] already has<br>
      &nbsp;&nbsp; assignments for many NAT logging events.&nbsp; For convenience, this<br>
      &nbsp;&nbsp; document uses those same IEs.&nbsp; However, as stated earlier, this<br>
      &nbsp;&nbsp; document is not defining IPFIX or NetFlow v9 as the framework
      for<br>
      &nbsp;&nbsp; logging.&nbsp; Rather, the information contained in these elements
      is<br>
      <br>
      SD: I got lost on "these elements" - is that "the elements in the
      existing registry"<br>
      <br>
      &nbsp;&nbsp; within the scope of this document.<br>
      <br>
      &nbsp;&nbsp; This document assumes that the NAT device will use the existing
      IPFIX<br>
      &nbsp;&nbsp; framework to send the log events to the collector.&nbsp; This would
      mean<br>
      &nbsp;&nbsp; that the NAT device will specify the template that it is going
      to use<br>
      &nbsp;&nbsp; for each of the events.&nbsp; The templates can be of varying length
      and<br>
      &nbsp;&nbsp; there could be multiple templates that a NAT device could use
      to log<br>
      &nbsp;&nbsp; the events.<br>
      <br>
      &nbsp;&nbsp; The implementation details of the collector application is
      beyond the<br>
      &nbsp;&nbsp; scope of this document.<br>
      <br>
      &nbsp;&nbsp; The optimization of logging the NAT events are left to the<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^<br>
      &nbsp;&nbsp; implementation and are beyond the scope of this document.<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^<br>
      SD: It's a nit, but those "are"s should be "is"s.<br>
      <br>
      4.&nbsp; Applicability<br>
      <br>
      &nbsp;&nbsp; NAT logging based on IPFIX uses binary encoding and hence is
      very<br>
      &nbsp;&nbsp; efficient.&nbsp; IPFIX based logging is recommended for environments
      where<br>
      &nbsp;&nbsp; a high volume of logging is required, for example, where
      per-flow<br>
      &nbsp;&nbsp; logging is needed.&nbsp; However, IPFIX based logging requires a
      collector<br>
      &nbsp;&nbsp; that processes the binary data and requires a network
      management<br>
      &nbsp;&nbsp; application that converts this binary data to a human readable<br>
      &nbsp;&nbsp; format.<br>
      <br>
      5.&nbsp; Event based logging<br>
      <br>
      &nbsp;&nbsp; An event in a NAT device can be viewed as a happening as it
      relates<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^<br>
      SD: Is this "a state transition"? I found "a happening" somewhat
      odd.<br>
      <br>
      &nbsp;&nbsp; to the management of NAT resources.&nbsp; The creation and deletion
      of NAT<br>
      &nbsp;&nbsp; sessions and bindings are examples of events as it results in
      the<br>
      &nbsp;&nbsp; resources (addresses and ports) being allocated or freed.&nbsp; The
      events<br>
      &nbsp;&nbsp; can happen either through the processing of data packets
      flowing<br>
      &nbsp;&nbsp; through the NAT device or through an external entity installing<br>
      &nbsp;&nbsp; policies on the NAT router or as a result of an asynchronous
      event<br>
      &nbsp;&nbsp; like a timer.&nbsp; The list of events are provided in Section 4.1.&nbsp;
      Each<br>
      &nbsp;&nbsp; of these events SHOULD be logged, unless they are
      administratively<br>
      &nbsp;&nbsp; prohibited.&nbsp; A NAT device MAY log these events to multiple
      collectors<br>
      &nbsp;&nbsp; if redundancy is required.&nbsp; The network administrator will
      specify<br>
      &nbsp;&nbsp; the collectors to which the log records are to be sent.<br>
      <br>
      &nbsp;&nbsp; A collector may receive NAT events from multiple CGN devices
      and<br>
      &nbsp;&nbsp; should be able to distinguish between the devices.&nbsp; Each CGN
      device<br>
      &nbsp;&nbsp; ^^^^^^<br>
      SD: I'm not sure why this isn't a SHOULD, or even a MUST.<br>
      <br>
      &nbsp;&nbsp; should have a unique source ID to identify themselves.&nbsp; The
      source ID<br>
      &nbsp;&nbsp; ^^^^^^<br>
      SD: Again, I'm not sure why this isn't a SHOULD, or even a MUST.<br>
      <br>
      &nbsp;&nbsp; is part of the IPFIX template and data exchange.<br>
      <br>
      &nbsp;&nbsp; Prior to logging any events, the NAT device MUST send the
      template of<br>
      &nbsp;&nbsp; the record to the collector to advertise the format of the data<br>
      &nbsp;&nbsp; record that it is using to send the events.&nbsp; The templates can
      be<br>
      &nbsp;&nbsp; exchanged as frequently as required given the reliability of
      the<br>
      &nbsp;&nbsp; connection.&nbsp; There SHOULD be a configurable timer for
      controlling the<br>
      &nbsp;&nbsp; template refresh.&nbsp; NAT device SHOULD combine as many events as<br>
      &nbsp;&nbsp; possible in a single packet to effectively utilize the network<br>
      &nbsp;&nbsp; bandwidth.<br>
      <br>
      5.1.&nbsp; Logging of destination information<br>
      <br>
      &nbsp;&nbsp; Logging of destination information in a NAT event has been
      discussed<br>
      &nbsp;&nbsp; in [RFC6302] and [RFC6888].&nbsp; Logging of destination information<br>
      &nbsp;&nbsp; increases the size of each record and increases the need for
      storage<br>
      &nbsp;&nbsp; considerably.&nbsp; It increases the number of log events generated<br>
      &nbsp;&nbsp; because when the same user connects to a different destination,
      it<br>
      &nbsp;&nbsp; results in a log record per destination address.&nbsp; Logging of<br>
      &nbsp;&nbsp; destination information also results in the loss of privacy and
      hence<br>
      &nbsp;&nbsp; should be done with caution.&nbsp; However, this draft provides the<br>
      &nbsp;&nbsp; necessary fields to log the destination information in cases
      where<br>
      &nbsp;&nbsp; they are required to be logged.<br>
      <br>
      5.2.&nbsp; Information Elements<br>
      <br>
      &nbsp;&nbsp; The templates could contain a subset of the Information
      Elements(IEs)<br>
      &nbsp;&nbsp; shown in Table 1 depending upon the event being logged.&nbsp; For
      example<br>
      &nbsp;&nbsp; a NAT44 session creation template record will contain,<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^<br>
      SD: Is this the only possible NAT44 template? If so, fine, but if
      not, perhaps "could contain", or "typically contains"?<br>
      <br>
      &nbsp;&nbsp; {sourceIPv4Adress, postNATSourceIPv4Address,
      destinationIpv4Address,<br>
      &nbsp;&nbsp; postNATDestinationIPv4Address, sourceTransportPort,<br>
      &nbsp;&nbsp; postNAPTSourceTransportPort, destinationTransportPort,<br>
      &nbsp;&nbsp; postNAPTDestTransportPort, internalAddressRealm, natEvent,
      timeStamp}<br>
      <br>
      &nbsp;&nbsp; An example of the actual event data record is shown below - in
      a<br>
      &nbsp;&nbsp; readable form<br>
      <br>
      &nbsp;&nbsp; {192.168.16.1, 201.1.1.100, 207.85.231.104, 207.85.231.104,
      14800,<br>
      &nbsp;&nbsp; 1024, 80, 80, 0, 1, 09:20:10:789}<br>
      <br>
      &nbsp;&nbsp; A single NAT device could be exporting multiple templates and
      the<br>
      &nbsp;&nbsp; collector should support receiving multiple templates from the
      same<br>
      &nbsp;&nbsp; source.observationTimeMilliseconds<br>
      <br>
      &nbsp;&nbsp; The following is the table of all the IE's that a CGN device
      would<br>
      &nbsp;&nbsp; need to export the events.&nbsp; The formats of the IE's and the
      IPFIX IDs<br>
      &nbsp;&nbsp; are listed below.<br>
      <br>
      SD: I noticed that some IEs below have a name that matches
      <a class="moz-txt-link-freetext" href="http://www.iana.org/assignments/ipfix/ipfix.xhtml#ipfix-information-elements">http://www.iana.org/assignments/ipfix/ipfix.xhtml#ipfix-information-elements</a>
      for the same IPFIX ID number, but others do not ("timeStamp" here
      doesn't match "observationTimeMilliseconds", but both are IPFIX ID
      323, aren't they?) Is there a reason to use names that don't match
      the IANA registry?<br>
      <br>
      &nbsp;&nbsp;
      +----------------------------------+--------+-------+---------------+<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; Size |&nbsp; IANA |&nbsp;
      Description&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | (bits) | IPFIX
      |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; ID
      |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;
      +----------------------------------+--------+-------+---------------+<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp; 323 |&nbsp; System
      Time&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; when
      the&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;
      event&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;
      occured.&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natInstanceId&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; TBD |&nbsp; NAT
      Instance |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;
      Identifier&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; vlanID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; 58 |&nbsp;&nbsp; VLAN ID
      in&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; case
      of&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;
      overlapping&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;
      networks&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 234 |&nbsp;&nbsp; VRF ID
      in&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; case
      of&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;
      overlapping&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;
      networks&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv4Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp; Source
      IPv4&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;
      Address&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv4Address&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 225 |&nbsp;&nbsp;
      Translated&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Source
      IPv4&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;
      Address&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; 4 |&nbsp;&nbsp;
      Transport&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;
      protocol&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceTransportPort&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; 7 |&nbsp; Source
      Port&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp; postNAPTsourceTransportPort&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp; 227 |&nbsp;&nbsp;
      Translated&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Source
      port&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationIPv4Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; 12 |&nbsp;
      Destination&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; IPv4
      Address |<br>
      &nbsp;&nbsp; |&nbsp; postNATDestinationIPv4Address&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 226 |&nbsp;&nbsp;
      Translated&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      IPv4&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;
      destination&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;
      address&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; destinationTransportPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; 11 |&nbsp;
      Destination&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      port&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; | postNAPTdestinationTransportPort |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp; 228 |&nbsp;&nbsp;
      Translated&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;
      Destination&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      port&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv6Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 27 |&nbsp;&nbsp; 128 |&nbsp; Source
      IPv6&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;
      address&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationIPv6Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp; 28 |&nbsp;
      Destination&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; IPv6
      address |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv6Address&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp; 281 |&nbsp;&nbsp;
      Translated&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; source
      IPv6&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;
      addresss&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp; postNATDestinationIPv6Address&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp; 282 |&nbsp;&nbsp;
      Translated&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;
      Destination&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; IPv6
      address |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; internalAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp; 229 |&nbsp;&nbsp;&nbsp;&nbsp;
      Source&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Address
      Realm |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; externalAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp; TBD |&nbsp;
      Destination&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Address
      Realm |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp; 230 | Type of
      Event |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; portRangeStart&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp; 361 |&nbsp;&nbsp;
      Allocated&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; port
      block&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;
      start&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; portRangeEnd&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp; 362 |&nbsp;&nbsp;
      Allocated&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; Port
      block&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      end&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natPoolID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 283 |&nbsp;&nbsp;&nbsp; NAT
      pool&nbsp;&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;
      Identifier&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natLimitEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; TBD |&nbsp; Limit
      event&nbsp; |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;
      identifier&nbsp; |<br>
      &nbsp;&nbsp;
      +----------------------------------+--------+-------+---------------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 1: Template format Table<br>
      <br>
      5.3.&nbsp; Definition of NAT Events<br>
      <br>
      &nbsp;&nbsp; The following are the list of NAT events and the proposed event<br>
      &nbsp;&nbsp; values.&nbsp; The list can be expanded in the future as necessary.&nbsp;
      The<br>
      &nbsp;&nbsp; data record will have the corresponding natEvent value to
      identify<br>
      &nbsp;&nbsp; the event that is being logged.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +--------------------------+--------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Event Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Values |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +--------------------------+--------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT44 Session create&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT44 Session delete&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | NAT Addresses exhausted&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT64 Session create&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT64 Session delete&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 5 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT44 BIB create&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 6 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT44 BIB delete&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 7 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT64 BIB create&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT64 BIB delete&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 9 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT ports exhausted&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 10 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Quota exceeded&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 11 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Address binding create&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 12 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Address binding delete&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 13 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Port block allocation&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 14 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Port block de-allocation |&nbsp;&nbsp;&nbsp;&nbsp; 15 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; Threshold reached&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +--------------------------+--------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 2: NAT Event ID table<br>
      <br>
      5.4.&nbsp; Quota exceeded Event types<br>
      <br>
      &nbsp;&nbsp; The following table shows the sub event types for the Quota
      exceeded<br>
      &nbsp;&nbsp; or limits reached event.&nbsp; The events that can be reported are
      the<br>
      &nbsp;&nbsp; Maximum session entries limit reached, Maximum BIB entries
      limit<br>
      &nbsp;&nbsp; reached, Maximum session/BIB entries per user limit reached and<br>
      &nbsp;&nbsp; maximum subscribers or hosts limit reached.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------------------------+--------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Quota Exceeded Event Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Values |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------------------------+--------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Maximum Session entries&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Maximum BIB entries&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Maximum entries per user&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Maximum active hosts or subscribers&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Maximum fragments pending reassembly |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 5 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------------------------+--------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 3: Quota Exceeded event table<br>
      <br>
      5.5.&nbsp; Threshold reached Event types<br>
      <br>
      &nbsp;&nbsp; The following table shows the sub event types for the threshold<br>
      &nbsp;&nbsp; reached event.&nbsp; The administrator can configure the thresholds
      and<br>
      &nbsp;&nbsp; whenever the threshold is reached or exceeded, the
      corresponding<br>
      &nbsp;&nbsp; events are generated.<br>
      <br>
      &nbsp;&nbsp; The address pool high threshold event will be reported when the<br>
      &nbsp;&nbsp; address pool reaches a high water mark as defined by the
      operator.<br>
      &nbsp;&nbsp; This will sever as an indication that the operator might have
      to add<br>
      &nbsp;&nbsp; more addresses to the pool or an indication that the subsequent
      users<br>
      &nbsp;&nbsp; may be denied NAT translation mappings.<br>
      <br>
      &nbsp;&nbsp; The address and port mapping high threshold event is generated,
      when<br>
      &nbsp;&nbsp; the number of ports in the configured address pool has reached
      a<br>
      &nbsp;&nbsp; configured threshold.<br>
      <br>
      &nbsp;&nbsp; The per-user address and port mapping high threshold is
      generated<br>
      &nbsp;&nbsp; when a single user uses more address and port mapping than a<br>
      &nbsp;&nbsp; configured threshold.<br>
      <br>
      &nbsp;&nbsp;
      +---------------------------------------------------------+--------+<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Threshold Exceeded Event Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |
      Values |<br>
      &nbsp;&nbsp;
      +---------------------------------------------------------+--------+<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Address pool high threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1 |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Address pool low threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2 |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Address and port mapping high threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3 |<br>
      &nbsp;&nbsp; |&nbsp; Address and port mapping per user high threshold event
      |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4 |<br>
      &nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Global Address mapping high threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 5 |<br>
      &nbsp;&nbsp;
      +---------------------------------------------------------+--------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 4: Threshold event table<br>
      <br>
      5.6.&nbsp; Templates for NAT Events<br>
      <br>
      &nbsp;&nbsp; The following is the template of events that will have to
      logged.<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      ^^^^^^^^^^^^^^^^^^^<br>
      <br>
      SD: I think this is a nit, but the sentence is garbled. "will be
      logged"?<br>
      <br>
      &nbsp;&nbsp; The events below are identified at the time of this writing but
      the<br>
      &nbsp;&nbsp; events are expandable.&nbsp; Depending on the implementation and<br>
      &nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^<br>
      SD: this is a nit, but "set of events is extensible", I think.<br>
      <br>
      &nbsp;&nbsp; configuration various IE's specified can be included or
      ignored.<br>
      <br>
      5.6.1.&nbsp; NAT44 create and delete session events<br>
      <br>
      &nbsp;&nbsp; These events will be generated when a NAT44 session is created
      or<br>
      &nbsp;&nbsp; deleted.&nbsp; The template will be the same, the natEvent will
      indicate<br>
      &nbsp;&nbsp; whether it is a create or a delete event.&nbsp; The following is a<br>
      &nbsp;&nbsp; template of the event.<br>
      <br>
      &nbsp;&nbsp; The destination address and port information is optional as
      required<br>
      &nbsp;&nbsp; by [RFC6888].&nbsp; However, when the destination information is<br>
      &nbsp;&nbsp; suppressed, the session log event contains the same information
      as<br>
      &nbsp;&nbsp; the BIB event.&nbsp; In such cases, the NAT device SHOULD NOT send
      both<br>
      &nbsp;&nbsp; BIB and session events.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      +----------------------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      +----------------------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; vlanID/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv4Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv4Address&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceTransportPort&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNAPTsourceTransportPort&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationIPv4Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; postNATDestinationIPv4Address&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; destinationTransportPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTdestinationTransportPort |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; internalAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; externalAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      +----------------------------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 5: NAT44 Session delete/create template<br>
      <br>
      5.6.2.&nbsp; NAT64 create and delete session events<br>
      <br>
      &nbsp;&nbsp; These events will be generated when a NAT64 session is created
      or<br>
      &nbsp;&nbsp; deleted.&nbsp; The following is a template of the event.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      +----------------------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      +----------------------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; vlanID/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv6Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv4Address&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceTransportPort&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNAPTsourceTransportPort&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationIPv6Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; postNATDestinationIPv4Address&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; destinationTransportPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTdestinationTransportPort |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; internalAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; externalAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;
      |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      +----------------------------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 6: NAT64 session create/delete event template<br>
      <br>
      5.6.3.&nbsp; NAT44 BIB create and delete events<br>
      <br>
      &nbsp;&nbsp; These events will be generated when a NAT44 Bind entry is
      created or<br>
      &nbsp;&nbsp; deleted.&nbsp; The following is a template of the event.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; vlanID/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv4Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNATSourceIPv4Address&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; sourceTransportPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTsourceTransportPort |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; internalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; externalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 7: NAT44 BIB create/delete event template<br>
      <br>
      5.6.4.&nbsp; NAT64 BIB create and delete events<br>
      <br>
      &nbsp;&nbsp; These events will be generated when a NAT64 Bind entry is
      created or<br>
      &nbsp;&nbsp; deleted.&nbsp; The following is a template of the event.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; vlanID/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv6Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNATSourceIPv4Address&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; sourceTransportPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTsourceTransportPort |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; internalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; externalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 8: NAT64 BIB create/delete event template<br>
      <br>
      5.6.5.&nbsp; Addresses Exhausted event<br>
      <br>
      &nbsp;&nbsp; This event will be generated when a NAT device runs out of
      global<br>
      &nbsp;&nbsp; IPv4 addresses in a given pool of addresses.&nbsp; Typically, this
      event<br>
      &nbsp;&nbsp; would mean that the NAT device wont be able to create any new<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^<br>
      SD: "won't"<br>
      <br>
      &nbsp;&nbsp; translations until some addresses/ports are freed.&nbsp; This event
      SHOULD<br>
      &nbsp;&nbsp; be rate limited as many packets hitting the device at the same
      time<br>
      &nbsp;&nbsp; will trigger a burst of addresses exhausted events.<br>
      <br>
      &nbsp;&nbsp; The following is a template of the event.&nbsp; Note that either the
      NAT<br>
      &nbsp;&nbsp; pool name or the nat pool identifier should be logged, but not
      both.<br>
      <br>
      SD: I lack understanding, but I didn't see anything that looked
      like a NAT pool name in the template. Did I miss something?<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; Field Name&nbsp; | Size (bits) | Mandatory |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; timeStamp&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | natInstanceID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; natPoolID&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 9: Address Exhausted event template<br>
      <br>
      5.6.6.&nbsp; Ports Exhausted event<br>
      <br>
      &nbsp;&nbsp; This event will be generated when a NAT device runs out of
      ports for<br>
      &nbsp;&nbsp; a global IPv4 address.&nbsp; Port exhaustion shall be reported per<br>
      &nbsp;&nbsp; protocol (UDP, TCP etc).&nbsp; This event SHOULD be rate limited as
      many<br>
      &nbsp;&nbsp; packets hitting the device at the same time will trigger a
      burst of<br>
      &nbsp;&nbsp; port exhausted events.<br>
      <br>
      &nbsp;&nbsp; The following is a template of the event.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +--------------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +--------------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNATSourceIPv4Address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; protocolIdentifier&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +--------------------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 10: Ports Exhausted event template<br>
      <br>
      5.6.7.&nbsp; Quota exceeded events<br>
      <br>
      &nbsp;&nbsp; This event will be generated when a NAT device cannot allocate<br>
      &nbsp;&nbsp; resources as a result of an administratively defined policy.&nbsp;
      The<br>
      &nbsp;&nbsp; quota exceeded event templates are described below<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^<br>
      SD: missing period<br>
      <br>
      5.6.7.1.&nbsp; Maximum session entries exceeded<br>
      <br>
      &nbsp;&nbsp; The maximum session entries exceeded is generated when the<br>
      &nbsp;&nbsp; administratively configured limit is reached.&nbsp; The following is
      the<br>
      &nbsp;&nbsp; template of the event.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; natInstanceID&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; natLimitEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | configuredLimit |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 11: Session Entries Exceeded event template<br>
      <br>
      5.6.7.2.&nbsp; Maximum BIB entries exceeded<br>
      <br>
      &nbsp;&nbsp; The maximum BIB entries exceeded is generated when the<br>
      &nbsp;&nbsp; administratively configured limit is reached.&nbsp; The following is
      the<br>
      &nbsp;&nbsp; template of the event.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; natInstanceID&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; natLimitEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | configuredLimit |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 12: BIB Entries Exceeded event template<br>
      <br>
      5.6.7.3.&nbsp; Maximum entries per user exceeded<br>
      <br>
      &nbsp;&nbsp; This event is generated when a single user reaches the<br>
      &nbsp;&nbsp; administratively configured limit.&nbsp; The following is the
      template of<br>
      &nbsp;&nbsp; the event.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------+-------------+---------------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) |&nbsp;&nbsp; Mandatory&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------+-------------+---------------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; natLimitEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; configuredLimit&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | vlanID/ingressVRFID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; sourceIPv4 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 | Yes for NAT44 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; sourceIPv6 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 | Yes for NAT64 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------+-------------+---------------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 13: Per-user Entries Exceeded event template<br>
      <br>
      5.6.7.4.&nbsp; Maximum active host or subscribers exceeded<br>
      <br>
      &nbsp;&nbsp; This event is generated when the number of allowed hosts or<br>
      &nbsp;&nbsp; subscribers reaches the administratively configured limit.&nbsp; The<br>
      &nbsp;&nbsp; following is the template of the event.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; natInstanceID&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; natLimitEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | configuredLimit |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-----------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 14: Maximum hosts/subscribers Exceeded event
      template<br>
      <br>
      5.6.7.5.&nbsp; Maximum fragments pending reassembly exceeded<br>
      <br>
      &nbsp;&nbsp; This event is generated when the number of fragments pending<br>
      &nbsp;&nbsp; reassembly reaches the administratively configured limit.&nbsp; The<br>
      &nbsp;&nbsp; following is the template of the event.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +----------------------+-------------+---------------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) |&nbsp;&nbsp; Mandatory&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +----------------------+-------------+---------------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; natLimitEvent&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; configuredLimit&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | internalAddressRealm |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | vlanID/ingressVRFID&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; sourceIPv4 address&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 | Yes for NAT44 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; sourceIPv6 address&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 | Yes for NAT64 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +----------------------+-------------+---------------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 15: Maximum fragments pending reassembly Exceeded
      event<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; template<br>
      <br>
      5.6.8.&nbsp; Threshold reached events<br>
      <br>
      &nbsp;&nbsp; This event will be generated when a NAT device reaches a
      operator<br>
      &nbsp;&nbsp; configured threshold when allocating resources.&nbsp; The threshold<br>
      &nbsp;&nbsp; reached events are described in the section above.&nbsp; The
      following is<br>
      &nbsp;&nbsp; a template of the individual events.<br>
      <br>
      5.6.8.1.&nbsp; Address pool high or low threshold reached<br>
      <br>
      &nbsp;&nbsp; This event is generated when the high or low threshold is
      reached for<br>
      &nbsp;&nbsp; the address pool.&nbsp; The template is the same for both high and
      low<br>
      &nbsp;&nbsp; threshold events<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; natInstanceID&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | natThresholdEvent |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; natPoolID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; configuredLimit&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-------------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp; Table 16: Address pool high/low threshold reached event
      template<br>
      <br>
      5.6.8.2.&nbsp; Address and port high threshold reached<br>
      <br>
      &nbsp;&nbsp; This event is generated when the high threshold is reached for
      the<br>
      &nbsp;&nbsp; address pool and ports.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; natInstanceID&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | natThresholdEvent |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; configuredLimit&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +-------------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 17: Address port high threshold reached event
      template<br>
      <br>
      5.6.8.3.&nbsp; Per-user Address and port high threshold reached<br>
      <br>
      &nbsp;&nbsp; This event is generated when the high threshold is reached for
      the<br>
      &nbsp;&nbsp; per-user address pool and ports.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------+-------------+---------------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) |&nbsp;&nbsp; Mandatory&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------+-------------+---------------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; natThresholdEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; configuredLimit&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | vlanID/ingressVRFID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; sourceIPv4 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 | Yes for NAT44 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; sourceIPv6 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 | Yes for NAT64 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------+-------------+---------------+<br>
      <br>
      &nbsp;&nbsp; Table 18: Per-user Address port high threshold reached event
      template<br>
      <br>
      5.6.8.4.&nbsp; Global Address mapping high threshold reached<br>
      <br>
      &nbsp;&nbsp; This event is generated when the high is reached for the
      per-user<br>
      &nbsp;&nbsp; address pool and ports.&nbsp; This is generated only by NAT devices
      that<br>
      &nbsp;&nbsp; use a address pooling behavior of paired.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------+-------------+-----------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; natThresholdEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; configuredLimit&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | vlanID/ingressVRFID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +---------------------+-------------+-----------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 19: Global Address mapping high threshold reached
      event<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; template<br>
      <br>
      5.6.9.&nbsp; Address binding create and delete events<br>
      <br>
      &nbsp;&nbsp; These events will be generated when a NAT device binds a local<br>
      &nbsp;&nbsp; address with a global address and when the global address is
      freed.<br>
      &nbsp;&nbsp; This binding event happens when the first packet of the first
      flow<br>
      &nbsp;&nbsp; from a host in the private realm.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;
      +--------------------------------+-------------+---------------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) |&nbsp;&nbsp;
      Mandatory&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;
      +--------------------------------+-------------+---------------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv4 address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 | Yes for
      NAT44 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv6 address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 | Yes for
      NAT64 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; | Translated Source IPv4 Address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;
      +--------------------------------+-------------+---------------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 20: NAT Address Binding template<br>
      <br>
      5.6.10.&nbsp; Port block allocation and de-allocation<br>
      <br>
      &nbsp;&nbsp; This event will be generated when a NAT device
      allocates/de-allocates<br>
      &nbsp;&nbsp; ports in a bulk fashion, as opposed to allocating a port on a
      per<br>
      &nbsp;&nbsp; flow basis.<br>
      <br>
      &nbsp;&nbsp; portRangeStart represents the starting value of the range.<br>
      <br>
      &nbsp;&nbsp; portRangeEnd represents the ending value of the range.<br>
      <br>
      &nbsp;&nbsp; NAT devices would do this in order to reduce logs and
      potentially to<br>
      &nbsp;&nbsp; limit the number of connections a subscriber is allowed to
      use.&nbsp; In<br>
      &nbsp;&nbsp; the following Port Block allocation template, the
      portRangeStart and<br>
      &nbsp;&nbsp; portRangeEnd must be specified.<br>
      <br>
      <br>
      Sivakumar &amp; Penno&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Expires August 15, 2014&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      [Page 17]<br>
      <br>
      Internet-Draft&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IPFIX IEs for NAT logging&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      February 2014<br>
      <br>
      &nbsp;&nbsp; It is up to the implementation to choose to consolidate log
      records<br>
      &nbsp;&nbsp; in case two consecutive port ranges for the same user are
      allocated<br>
      &nbsp;&nbsp; or freed.<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;
      +--------------------------------+-------------+---------------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) |&nbsp;&nbsp;
      Mandatory&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;
      +--------------------------------+-------------+---------------+<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv4 address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 | Yes for
      NAT44 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv6 address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 | Yes for
      NAT64 |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; | Translated Source IPv4 Address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; portRangeStart&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; portRangeEnd&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
      &nbsp;&nbsp;&nbsp;&nbsp;
      +--------------------------------+-------------+---------------+<br>
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 21: NAT Port Block Allocation event template<br>
      <br>
      6.&nbsp; Encoding<br>
      <br>
      6.1.&nbsp; IPFIX<br>
      <br>
      &nbsp;&nbsp; This document uses IPFIX as the encoding mechanism to describe
      the<br>
      &nbsp;&nbsp; logging of NAT events.&nbsp; However, the information that should be<br>
      &nbsp;&nbsp; logged SHOULD be the same irrespective of what kind of encoding<br>
      &nbsp;&nbsp; scheme is used.&nbsp; IPFIX is chosen because is it an IETF standard
      that<br>
      &nbsp;&nbsp; meets all the needs for a reliable logging mechanism.&nbsp; IPFIX
      provides<br>
      &nbsp;&nbsp; the flexibility to the logging device to define the data sets
      that it<br>
      &nbsp;&nbsp; is logging.&nbsp; The IEs specified for logging MUST be the same<br>
      &nbsp;&nbsp; irrespective of the encoding mechanism used.<br>
      <br>
      7.&nbsp; Acknowledgements<br>
      <br>
      &nbsp;&nbsp; Thanks to Dan Wing, Selvi Shanmugam, Mohamed Boucadir, Jacni
      Qin<br>
      &nbsp;&nbsp; Ramji Vaithianathan, Simon Perreault, Jean-Francois Tremblay,
      Paul<br>
      &nbsp;&nbsp; Aitken and Julia Renouard for their review and comments.<br>
      <br>
      8.&nbsp; IANA Considerations<br>
      <br>
      &nbsp;&nbsp; The following information elements are requested from IANA
      IPFIX<br>
      &nbsp;&nbsp; registry.<br>
      <br>
      &nbsp;&nbsp; natInstanceId<br>
      <br>
      &nbsp;&nbsp; externalAddressRealm<br>
      <br>
      &nbsp;&nbsp; natLimitEvent<br>
      <br>
      9.&nbsp; Management Considerations<br>
      <br>
      &nbsp;&nbsp; This section considers requirements for management of the log
      system<br>
      &nbsp;&nbsp; to support logging of the events described above.&nbsp; It first
      covers<br>
      &nbsp;&nbsp; requirements applicable to log management in general.&nbsp; Any
      additional<br>
      &nbsp;&nbsp; standardization required to fullfil these requirements is out
      of<br>
      &nbsp;&nbsp; scope of the present document.&nbsp; Some management considerations
      is<br>
      &nbsp;&nbsp; covered in [I-D.behave-syslog-nat-logging].&nbsp; This document
      covers the<br>
      &nbsp;&nbsp; additional considerations.<br>
      <br>
      9.1.&nbsp; Ability to collect events from multiple NAT devices<br>
      <br>
      &nbsp;&nbsp; An IPFIX collector should be able to collect events from
      multiple NAT<br>
      &nbsp;&nbsp; devices and be able to decipher events based on the sourceID in
      the<br>
      &nbsp;&nbsp; IPFIX header.<br>
      <br>
      9.2.&nbsp; Ability to suppress events<br>
      <br>
      &nbsp;&nbsp; The exhaustion events can be overwhelming during traffic bursts
      and<br>
      &nbsp;&nbsp; hence should be handled by the NAT devices to rate limit them
      before<br>
      &nbsp;&nbsp; sending them to the collectors.&nbsp; For eg. when the port
      exhaustion<br>
      &nbsp;&nbsp; happens during bursty conditions, instead of sending a port<br>
      &nbsp;&nbsp; exhaustion event for every packet, the exhaustion events should
      be<br>
      &nbsp;&nbsp; rate limited by the NAT device.<br>
      <br>
      10.&nbsp; Security Considerations<br>
      <br>
      &nbsp;&nbsp; None.<br>
      <br>
      11.&nbsp; References<br>
      <br>
      11.1.&nbsp; Normative References<br>
      <br>
      &nbsp;&nbsp; [RFC2119]&nbsp; Bradner, S., "Key words for use in RFCs to Indicate<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Requirement Levels", BCP 14, RFC 2119, March 1997.<br>
      <br>
      &nbsp;&nbsp; [RFC2663]&nbsp; Srisuresh, P. and M. Holdrege, "IP Network Address<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Translator (NAT) Terminology and Considerations",
      RFC<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2663, August 1999.<br>
      <br>
      &nbsp;&nbsp; [RFC4787]&nbsp; Audet, F. and C. Jennings, "Network Address
      Translation<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; (NAT) Behavioral Requirements for Unicast UDP", BCP
      127,<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; RFC 4787, January 2007.<br>
      <br>
      &nbsp;&nbsp; [RFC5382]&nbsp; Guha, S., Biswas, K., Ford, B., Sivakumar, S., and
      P.<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Srisuresh, "NAT Behavioral Requirements for TCP",
      BCP 142,<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; RFC 5382, October 2008.<br>
      <br>
      &nbsp;&nbsp; [RFC6146]&nbsp; Bagnulo, M., Matthews, P., and I. van Beijnum,
      "Stateful<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NAT64: Network Address and Protocol Translation from
      IPv6<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Clients to IPv4 Servers", RFC 6146, April 2011.<br>
      <br>
      &nbsp;&nbsp; [RFC6302]&nbsp; Durand, A., Gashinsky, I., Lee, D., and S. Sheppard,<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "Logging Recommendations for Internet-Facing
      Servers", BCP<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 162, RFC 6302, June 2011.<br>
      <br>
      &nbsp;&nbsp; [RFC6888]&nbsp; Perreault, S., Yamagata, I., Miyakawa, S., Nakagawa,
      A.,<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; and H. Ashida, "Common Requirements for
      Carrier-Grade NATs<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; (CGNs)", BCP 127, RFC 6888, April 2013.<br>
      <br>
      11.2.&nbsp; Informative References<br>
      <br>
      &nbsp;&nbsp; [I-D.ietf-behave-syslog-nat-logging]<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Chen, Z., Zhou, C., Tsou, T., and T. Taylor, "Syslog<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Format for NAT Logging",
      draft-ietf-behave-syslog-nat-<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; logging-06 (work in progress), January 2014.<br>
      <br>
      &nbsp;&nbsp; [IPFIX-IANA]<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IANA, "IPFIX Information Elements registry",<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a class="moz-txt-link-rfc2396E" href="http://www.iana.org/assignments/ipfix">&lt;http://www.iana.org/assignments/ipfix&gt;</a>.<br>
      <br>
      &nbsp;&nbsp; [RFC5101bis]<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Claise, B. and B. Trammel, "Specification of the IP
      Flow<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Information eXport (IPFIX) Protocol for the Exchange
      of<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Flow Information", July 2013.<br>
      <br>
      &nbsp;&nbsp; [RFC5102bis]<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Claise, B. and B. Trammel, "Information Model for IP
      Flow<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Information eXport (IPFIX)", February 2013.<br>
      <br>
      &nbsp;&nbsp; [RFC5470]&nbsp; Sadasivan, G., Brownlee, N., Claise, B., and J.
      Quittek,<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "Architecture for IP Flow Information Export", RFC
      5470,<br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; March 2009.<br>
      <br>
      Authors' Addresses<br>
      <br>
      &nbsp;&nbsp; Senthil Sivakumar<br>
      &nbsp;&nbsp; Cisco Systems<br>
      &nbsp;&nbsp; 7100-8 Kit Creek Road<br>
      &nbsp;&nbsp; Research Triangle Park, North Carolina&nbsp; 27709<br>
      &nbsp;&nbsp; USA<br>
      <br>
      &nbsp;&nbsp; Phone: +1 919 392 5158<br>
      <br>
      &nbsp;&nbsp; Renaldo Penno<br>
      &nbsp;&nbsp; Cisco Systems<br>
      &nbsp;&nbsp; 170 W Tasman Drive<br>
      &nbsp;&nbsp; San Jose, California&nbsp; 95035<br>
      &nbsp;&nbsp; USA<br>
      <br>
      &nbsp;&nbsp; Email: <a class="moz-txt-link-abbreviated" href="mailto:repenno@cisco.com">repenno@cisco.com</a><br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      <br>
      Sivakumar &amp; Penno&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Expires August 15, 2014&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
      [Page 21]</font>
  </body>
</html>

--------------070305050403020606040406--


From nobody Mon May  5 08:16:49 2014
Return-Path: <ssenthil@cisco.com>
X-Original-To: behave@ietfa.amsl.com
Delivered-To: behave@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 636591A0911 for <behave@ietfa.amsl.com>; Fri,  2 May 2014 12:20:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.151
X-Spam-Level: 
X-Spam-Status: No, score=-10.151 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vpc7tEyGzi3Y for <behave@ietfa.amsl.com>; Fri,  2 May 2014 12:20:32 -0700 (PDT)
Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) by ietfa.amsl.com (Postfix) with ESMTP id 30B111A6FA9 for <behave@ietf.org>; Fri,  2 May 2014 12:20:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=162075; q=dns/txt; s=iport; t=1399058429; x=1400268029; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=SYYrvxeWZQ2JGooi9VHFl58Lh5ZZq1/r0ilLzc9HsiE=; b=YXi6JgK2yYz/9cGPsr2HYRMDszWn02IgFgwq6y4145cIYLiZJ3TpFPok HVRAxsdgcZbHgn6d+AZgz+fZs467YyUnVJFHFkIOHWHv4Ma/W/ZUAJ0Pe V9XQ0m48vqbeL4w8v7/cvYgOlo7LfmoTq9ou9Y8+/0sVvw1c0yvR8RYez Q=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AkwLAHLvY1OtJA2F/2dsb2JhbABPBwOCQkRPWLcaOYFaix+BERZ0giUBAQEEGgFMEg4CAgEIEQECAQIhAQYHGwYRFAMGCAIEAQ0FCYgkAxENw2wNhkQXBIwnEIEzAgEFBAEGAQMEHRsBEAcRhCgEjB2JHYIEgXKNFIVbgzRtgQABCBci
X-IronPort-AV: E=Sophos; i="4.97,973,1389744000"; d="scan'208,217"; a="40609647"
Received: from alln-core-11.cisco.com ([173.36.13.133]) by alln-iport-3.cisco.com with ESMTP; 02 May 2014 19:20:27 +0000
Received: from xhc-rcd-x04.cisco.com (xhc-rcd-x04.cisco.com [173.37.183.78]) by alln-core-11.cisco.com (8.14.5/8.14.5) with ESMTP id s42JKQn0027375 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Fri, 2 May 2014 19:20:27 GMT
Received: from xmb-rcd-x15.cisco.com ([169.254.5.122]) by xhc-rcd-x04.cisco.com ([fe80::200:5efe:173.37.183.34%12]) with mapi id 14.03.0123.003; Fri, 2 May 2014 14:20:26 -0500
From: "Senthil Sivakumar (ssenthil)" <ssenthil@cisco.com>
To: Spencer Dawkins <spencerdawkins.ietf@gmail.com>, "draft-ietf-behave-ipfix-nat-logging@tools.ietf.org" <draft-ietf-behave-ipfix-nat-logging@tools.ietf.org>
Thread-Topic: AD Evaluation of draft-ietf-behave-ipfix-nat-logging-03
Thread-Index: AQHPZXuW1xHWpTEStEWEs33L9nVI5ZstvOcA
Date: Fri, 2 May 2014 19:20:25 +0000
Message-ID: <CF89605B.1009FB%ssenthil@cisco.com>
References: <5362ADCB.4050802@gmail.com>
In-Reply-To: <5362ADCB.4050802@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.4.1.140326
x-originating-ip: [10.82.212.45]
Content-Type: multipart/alternative; boundary="_000_CF89605B1009FBssenthilciscocom_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/behave/1heZwdeSo0zT2uOhBYRbAKj6Rf8
X-Mailman-Approved-At: Mon, 05 May 2014 08:16:47 -0700
Cc: "behave@ietf.org" <behave@ietf.org>
Subject: Re: [BEHAVE] AD Evaluation of draft-ietf-behave-ipfix-nat-logging-03
X-BeenThere: behave@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: mailing list of BEHAVE IETF WG <behave.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/behave>, <mailto:behave-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/behave/>
List-Post: <mailto:behave@ietf.org>
List-Help: <mailto:behave-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 02 May 2014 19:20:43 -0000

--_000_CF89605B1009FBssenthilciscocom_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Hi Spencer,
Thanks for the thorough review.
Please see inline for [Senthil]. If you agree, I will submit another versio=
n fixing all the issues raised and agreed upon. I will wait for your respon=
se.

Thanks
Senthil

From: Spencer Dawkins <spencerdawkins.ietf@gmail.com<mailto:spencerdawkins.=
ietf@gmail.com>>
Date: Thursday, May 1, 2014 4:25 PM
To: "draft-ietf-behave-ipfix-nat-logging@tools.ietf.org<mailto:draft-ietf-b=
ehave-ipfix-nat-logging@tools.ietf.org>" <draft-ietf-behave-ipfix-nat-loggi=
ng@tools.ietf.org<mailto:draft-ietf-behave-ipfix-nat-logging@tools.ietf.org=
>>
Cc: "behave@ietf.org<mailto:behave@ietf.org>" <behave@ietf.org<mailto:behav=
e@ietf.org>>
Subject: AD Evaluation of draft-ietf-behave-ipfix-nat-logging-03
Resent-From: <draft-alias-bounces@tools.ietf.org<mailto:draft-alias-bounces=
@tools.ietf.org>>
Resent-To: <repenno@cisco.com<mailto:repenno@cisco.com>>, Senthil Sivakumar=
 <ssenthil@cisco.com<mailto:ssenthil@cisco.com>>
Resent-Date: Thursday, May 1, 2014 4:26 PM

Dear draft-ietf-behave-ipfix-nat-logging Authors,

I've completed my AD evaluation for this draft. I found some things I'd lik=
e to see changed before proceeding, but most are editorial. Please take a l=
ook, and let me know what you think.

My notes follow ... you should be able to find my questions and comments by=
 searching for "SD:".

Thanks,

Spencer

In the Abstract

   NAT devices are required to log events like creation and deletion of
                   ^^^^^^^^
SD: Is this required, like, legally required, or ? Is it more like "Operato=
rs need NAT devices to log events ..."?
[Senthil] : It is the later, the network operators require the NAT devices =
to be able to log events.


   translations and information about the resources it is managing.  The
   logs are required in many cases to identify an attacker or a host
   that was used to launch malicious attacks and/or for various other
   purposes of accounting.  Since there is no standard way of logging
   this information, different NAT devices behave differently and hence
                               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
SD: Is this "different NAT devices log this information differently"?
[Senthil] Correct, as the sentence says, "Since there is no standard way=85=
", each NAT device logs information in its own proprietary format.



   it is difficult to expect a consistent behavior.  The lack of a
   consistent way makes it difficult to write the collector applications
   that would receive this data and process it to present useful
   information.  This document describes the information that is
   required to be logged by the NAT devices.
   ^^^^^^^^^^^^^^^^^^^^^^^^
SD: Same as previous question - is this "logged by"?

[Senthil] If a NAT device is logging events, these are the requirements tha=
t a NAT device should adhere to.


2.  Introduction

   The IPFIX Protocol [RFC5101bis] defines a generic push mechanism for
   exporting information and events.  The IPFIX Information Model
   [IPFIX-IANA] defines a set of standard Information Elements (IEs)
   which can be carried by the IPFIX protocol.  This document details
   the IPFIX Information Elements(IEs) that are required for logging by
   a NAT device.  The document will specify the format of the IE's that
   are required to be logged by the NAT device and all the optional
       ^^^^^^^^^^^^^^^^^^^^^
SD: Now that we're in the document body, if this is required, shouldn't the=
re be a reference to where the requirements are stated?
[Senthil] This is the document that is specifying those requirements. Do yo=
u have any other suggestions of wording instead of "required by", would it =
be fine if I change the sentence from
"required to be logged" to "SHOULD be logged"?


   fields.  The fields specified in this document are gleaned from
   [RFC4787] and [RFC5382].

   Test [3GPP]
   ^^^^^^^^^^^
SD: Is something missing here? It's just the word "Test" and a reference.
[Senthil] Agree. I will remove this.



   This document and [I-D.behave-syslog-nat-logging] are provided in
   order to standardize the events and parameters to be recorded, using
   IPFIX [RFC5101bis] and SYSLOG [RFC5424]respectively.

3.  Scope

   This document provides the information model to be used for logging
   the NAT devices including Carrier Grade NAT (CGN) events.  This
                   ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
SD: This sentence seems somewhat turned around - "logging events", not "log=
ging the NAT devices".
[Senthil] Agree, I will change this to "logging the NAT events".


   document focuses exclusively on the specification of IPFIX IE's.
   This document does not provide guidance on the transport protocol
   like TCP, UDP or SCTP that is to be used to log NAT events.  The log
   events SHOULD NOT be lost but the choice of the actual transport
   protocol is beyond the scope of this document.

SD: I'm not understanding why this last sentence is needed, especially with=
 a normative requirement for what you do when you are doing something outsi=
de the scope of the document ...
[Senthil] Are you objecting to the second part of the last sentence "the ch=
oice of actual transport=85", I think the requirement is that the LOG event=
s should not be lost is valid.

   The existing IANA IPFIX IEs registry [IPFIX-IANA] already has
   assignments for many NAT logging events.  For convenience, this
   document uses those same IEs.  However, as stated earlier, this
   document is not defining IPFIX or NetFlow v9 as the framework for
   logging.  Rather, the information contained in these elements is

SD: I got lost on "these elements" - is that "the elements in the existing =
registry"
[Senthil] Yes. How about "Rather, the information elements as defined in th=
e IPFIX-IANA registry is within the scope of this document"?


   within the scope of this document.

   This document assumes that the NAT device will use the existing IPFIX
   framework to send the log events to the collector.  This would mean
   that the NAT device will specify the template that it is going to use
   for each of the events.  The templates can be of varying length and
   there could be multiple templates that a NAT device could use to log
   the events.

   The implementation details of the collector application is beyond the
   scope of this document.

   The optimization of logging the NAT events are left to the
                                              ^^^
   implementation and are beyond the scope of this document.
                      ^^^
SD: It's a nit, but those "are"s should be "is"s.
[Senthil] Ok.



4.  Applicability

   NAT logging based on IPFIX uses binary encoding and hence is very
   efficient.  IPFIX based logging is recommended for environments where
   a high volume of logging is required, for example, where per-flow
   logging is needed.  However, IPFIX based logging requires a collector
   that processes the binary data and requires a network management
   application that converts this binary data to a human readable
   format.

5.  Event based logging

   An event in a NAT device can be viewed as a happening as it relates
                                               ^^^^^^^^^
SD: Is this "a state transition"? I found "a happening" somewhat odd.
[Senthil] Yes, I can rephrase this as "viewed as a state transition as it r=
elates to" or "viewed as an action as it relates to", if that is ok.


   to the management of NAT resources.  The creation and deletion of NAT
   sessions and bindings are examples of events as it results in the
   resources (addresses and ports) being allocated or freed.  The events
   can happen either through the processing of data packets flowing
   through the NAT device or through an external entity installing
   policies on the NAT router or as a result of an asynchronous event
   like a timer.  The list of events are provided in Section 4.1.  Each
   of these events SHOULD be logged, unless they are administratively
   prohibited.  A NAT device MAY log these events to multiple collectors
   if redundancy is required.  The network administrator will specify
   the collectors to which the log records are to be sent.

   A collector may receive NAT events from multiple CGN devices and
   should be able to distinguish between the devices.  Each CGN device
   ^^^^^^
SD: I'm not sure why this isn't a SHOULD, or even a MUST.

   should have a unique source ID to identify themselves.  The source ID
   ^^^^^^
SD: Again, I'm not sure why this isn't a SHOULD, or even a MUST.

[Senthil] Well, this is NOT a statement for a NAT device, instead it is a c=
ollector that some application writer will
develop.


   is part of the IPFIX template and data exchange.

   Prior to logging any events, the NAT device MUST send the template of
   the record to the collector to advertise the format of the data
   record that it is using to send the events.  The templates can be
   exchanged as frequently as required given the reliability of the
   connection.  There SHOULD be a configurable timer for controlling the
   template refresh.  NAT device SHOULD combine as many events as
   possible in a single packet to effectively utilize the network
   bandwidth.

5.1.  Logging of destination information

   Logging of destination information in a NAT event has been discussed
   in [RFC6302] and [RFC6888].  Logging of destination information
   increases the size of each record and increases the need for storage
   considerably.  It increases the number of log events generated
   because when the same user connects to a different destination, it
   results in a log record per destination address.  Logging of
   destination information also results in the loss of privacy and hence
   should be done with caution.  However, this draft provides the
   necessary fields to log the destination information in cases where
   they are required to be logged.

5.2.  Information Elements

   The templates could contain a subset of the Information Elements(IEs)
   shown in Table 1 depending upon the event being logged.  For example
   a NAT44 session creation template record will contain,
                                            ^^^^
SD: Is this the only possible NAT44 template? If so, fine, but if not, perh=
aps "could contain", or "typically contains"?

[Senthil] Yes, this is all the information that a NAT44 need to export as i=
t is the least common denominator.


   {sourceIPv4Adress, postNATSourceIPv4Address, destinationIpv4Address,
   postNATDestinationIPv4Address, sourceTransportPort,
   postNAPTSourceTransportPort, destinationTransportPort,
   postNAPTDestTransportPort, internalAddressRealm, natEvent, timeStamp}

   An example of the actual event data record is shown below - in a
   readable form

   {192.168.16.1, 201.1.1.100, 207.85.231.104, 207.85.231.104, 14800,
   1024, 80, 80, 0, 1, 09:20:10:789}

   A single NAT device could be exporting multiple templates and the
   collector should support receiving multiple templates from the same
   source.observationTimeMilliseconds

   The following is the table of all the IE's that a CGN device would
   need to export the events.  The formats of the IE's and the IPFIX IDs
   are listed below.

SD: I noticed that some IEs below have a name that matches http://www.iana.=
org/assignments/ipfix/ipfix.xhtml#ipfix-information-elements for the same I=
PFIX ID number, but others do not ("timeStamp" here doesn't match "observat=
ionTimeMilliseconds", but both are IPFIX ID 323, aren't they?) Is there a r=
eason to use names that don't match the IANA registry?

[Senthil] Good question, in case of timeStamp, I was looking for something =
that already existed in the IPFIX registry rather than asking for a new one=
. However, the terminology of "observationTimeMilliseconds" is not the term=
inology that we use in the NAT drafts/rfc's. So I am open to suggestions he=
re. I can clarify in the description that is called observationTimeMilliSec=
onds". The other field is internalAddressRealm and externalAddresRealm, thi=
s is the terminology that we used in NAT MIB, syslog and other documents. H=
owever, when we defined the IPFIX IE, we didn=92t stick to the same termino=
logy, so I don=92t know if I can go and ask the IPFIX IANA to change the na=
me. Again I am open to suggestions, the dillema is whether I should stick t=
o the existing IPFIX IANA terminology or the behave documents terminology.


   +----------------------------------+--------+-------+---------------+
   |            Field Name            |   Size |  IANA |  Description  |
   |                                  | (bits) | IPFIX |               |
   |                                  |        |    ID |               |
   +----------------------------------+--------+-------+---------------+
   |            timeStamp             |     64 |   323 |  System Time  |
   |                                  |        |       |    when the   |
   |                                  |        |       |     event     |
   |                                  |        |       |    occured.   |
   |          natInstanceId           |     32 |   TBD |  NAT Instance |
   |                                  |        |       |   Identifier  |
   |              vlanID              |     16 |    58 |   VLAN ID in  |
   |                                  |        |       |    case of    |
   |                                  |        |       |  overlapping  |
   |                                  |        |       |    networks   |
   |           ingressVRFID           |     32 |   234 |   VRF ID in   |
   |                                  |        |       |    case of    |
   |                                  |        |       |  overlapping  |
   |                                  |        |       |    networks   |
   |        sourceIPv4Address         |     32 |     8 |  Source IPv4  |
   |                                  |        |       |    Address    |
   |     postNATSourceIPv4Address     |     32 |   225 |   Translated  |
   |                                  |        |       |  Source IPv4  |
   |                                  |        |       |    Address    |
   |        protocolIdentifier        |      8 |     4 |   Transport   |
   |                                  |        |       |    protocol   |
   |       sourceTransportPort        |     16 |     7 |  Source Port  |
   |   postNAPTsourceTransportPort    |     16 |   227 |   Translated  |
   |                                  |        |       |  Source port  |
   |      destinationIPv4Address      |     32 |    12 |  Destination  |
   |                                  |        |       |  IPv4 Address |
   |  postNATDestinationIPv4Address   |     32 |   226 |   Translated  |
   |                                  |        |       |      IPv4     |
   |                                  |        |       |  destination  |
   |                                  |        |       |    address    |
   |     destinationTransportPort     |     16 |    11 |  Destination  |
   |                                  |        |       |      port     |
   | postNAPTdestinationTransportPort |     16 |   228 |   Translated  |
   |                                  |        |       |  Destination  |
   |                                  |        |       |      port     |
   |        sourceIPv6Address         |     27 |   128 |  Source IPv6  |
   |                                  |        |       |    address    |
   |      destinationIPv6Address      |    128 |    28 |  Destination  |
   |                                  |        |       |  IPv6 address |
   |     postNATSourceIPv6Address     |    128 |   281 |   Translated  |
   |                                  |        |       |  source IPv6  |
   |                                  |        |       |    addresss   |
   |  postNATDestinationIPv6Address   |    128 |   282 |   Translated  |
   |                                  |        |       |  Destination  |
   |                                  |        |       |  IPv6 address |
   |       internalAddressRealm       |      8 |   229 |     Source    |
   |                                  |        |       | Address Realm |
   |       externalAddressRealm       |      8 |   TBD |  Destination  |
   |                                  |        |       | Address Realm |
   |             natEvent             |      8 |   230 | Type of Event |
   |          portRangeStart          |     16 |   361 |   Allocated   |
   |                                  |        |       |   port block  |
   |                                  |        |       |     start     |
   |           portRangeEnd           |     16 |   362 |   Allocated   |
   |                                  |        |       |   Port block  |
   |                                  |        |       |      end      |
   |            natPoolID             |     32 |   283 |    NAT pool   |
   |                                  |        |       |   Identifier  |
   |          natLimitEvent           |     32 |   TBD |  Limit event  |
   |                                  |        |       |   identifier  |
   +----------------------------------+--------+-------+---------------+

                      Table 1: Template format Table

5.3.  Definition of NAT Events

   The following are the list of NAT events and the proposed event
   values.  The list can be expanded in the future as necessary.  The
   data record will have the corresponding natEvent value to identify
   the event that is being logged.

                   +--------------------------+--------+
                   |        Event Name        | Values |
                   +--------------------------+--------+
                   |   NAT44 Session create   |      1 |
                   |   NAT44 Session delete   |      2 |
                   | NAT Addresses exhausted  |      3 |
                   |   NAT64 Session create   |      4 |
                   |   NAT64 Session delete   |      5 |
                   |     NAT44 BIB create     |      6 |
                   |     NAT44 BIB delete     |      7 |
                   |     NAT64 BIB create     |      8 |
                   |     NAT64 BIB delete     |      9 |
                   |   NAT ports exhausted    |     10 |
                   |      Quota exceeded      |     11 |
                   |  Address binding create  |     12 |
                   |  Address binding delete  |     13 |
                   |  Port block allocation   |     14 |
                   | Port block de-allocation |     15 |
                   |    Threshold reached     |     16 |
                   +--------------------------+--------+

                        Table 2: NAT Event ID table

5.4.  Quota exceeded Event types

   The following table shows the sub event types for the Quota exceeded
   or limits reached event.  The events that can be reported are the
   Maximum session entries limit reached, Maximum BIB entries limit
   reached, Maximum session/BIB entries per user limit reached and
   maximum subscribers or hosts limit reached.

            +---------------------------------------+--------+
            |       Quota Exceeded Event Name       | Values |
            +---------------------------------------+--------+
            |        Maximum Session entries        |      1 |
            |          Maximum BIB entries          |      2 |
            |        Maximum entries per user       |      3 |
            |  Maximum active hosts or subscribers  |      4 |
            |  Maximum fragments pending reassembly |      5 |
            +---------------------------------------+--------+

                    Table 3: Quota Exceeded event table

5.5.  Threshold reached Event types

   The following table shows the sub event types for the threshold
   reached event.  The administrator can configure the thresholds and
   whenever the threshold is reached or exceeded, the corresponding
   events are generated.

   The address pool high threshold event will be reported when the
   address pool reaches a high water mark as defined by the operator.
   This will sever as an indication that the operator might have to add
   more addresses to the pool or an indication that the subsequent users
   may be denied NAT translation mappings.

   The address and port mapping high threshold event is generated, when
   the number of ports in the configured address pool has reached a
   configured threshold.

   The per-user address and port mapping high threshold is generated
   when a single user uses more address and port mapping than a
   configured threshold.

   +---------------------------------------------------------+--------+
   |              Threshold Exceeded Event Name              | Values |
   +---------------------------------------------------------+--------+
   |            Address pool high threshold event            |      1 |
   |             Address pool low threshold event            |      2 |
   |      Address and port mapping high threshold event      |      3 |
   |  Address and port mapping per user high threshold event |      4 |
   |       Global Address mapping high threshold event       |      5 |
   +---------------------------------------------------------+--------+

                      Table 4: Threshold event table

5.6.  Templates for NAT Events

   The following is the template of events that will have to logged.
                                                ^^^^^^^^^^^^^^^^^^^

SD: I think this is a nit, but the sentence is garbled. "will be logged"?

   The events below are identified at the time of this writing but the
   events are expandable.  Depending on the implementation and
   ^^^^^^^^^^^^^^^^^^^^^
SD: this is a nit, but "set of events is extensible", I think.

[Senthil] Agree. (to both comments).


   configuration various IE's specified can be included or ignored.

5.6.1.  NAT44 create and delete session events

   These events will be generated when a NAT44 session is created or
   deleted.  The template will be the same, the natEvent will indicate
   whether it is a create or a delete event.  The following is a
   template of the event.

   The destination address and port information is optional as required
   by [RFC6888].  However, when the destination information is
   suppressed, the session log event contains the same information as
   the BIB event.  In such cases, the NAT device SHOULD NOT send both
   BIB and session events.

      +----------------------------------+-------------+-----------+
      |            Field Name            | Size (bits) | Mandatory |
      +----------------------------------+-------------+-----------+
      |            timeStamp             |          64 |    Yes    |
      |          natInstanceID           |          32 |     No    |
      |       vlanID/ingressVRFID        |          32 |     No    |
      |        sourceIPv4Address         |          32 |    Yes    |
      |     postNATSourceIPv4Address     |          32 |    Yes    |
      |        protocolIdentifier        |           8 |    Yes    |
      |       sourceTransportPort        |          16 |    Yes    |
      |   postNAPTsourceTransportPort    |          16 |    Yes    |
      |      destinationIPv4Address      |          32 |     No    |
      |  postNATDestinationIPv4Address   |          32 |     No    |
      |     destinationTransportPort     |          16 |     No    |
      | postNAPTdestinationTransportPort |          16 |     No    |
      |       internalAddressRealm       |           8 |     No    |
      |       externalAddressRealm       |           8 |     No    |
      |             natEvent             |           8 |    Yes    |
      +----------------------------------+-------------+-----------+

               Table 5: NAT44 Session delete/create template

5.6.2.  NAT64 create and delete session events

   These events will be generated when a NAT64 session is created or
   deleted.  The following is a template of the event.

      +----------------------------------+-------------+-----------+
      |            Field Name            | Size (bits) | Mandatory |
      +----------------------------------+-------------+-----------+
      |            timeStamp             |          64 |    Yes    |
      |          natInstanceID           |          32 |     No    |
      |       vlanID/ingressVRFID        |          32 |     No    |
      |        sourceIPv6Address         |         128 |    Yes    |
      |     postNATSourceIPv4Address     |          32 |    Yes    |
      |        protocolIdentifier        |           8 |    Yes    |
      |       sourceTransportPort        |          16 |    Yes    |
      |   postNAPTsourceTransportPort    |          16 |    Yes    |
      |      destinationIPv6Address      |         128 |     No    |
      |  postNATDestinationIPv4Address   |          32 |     No    |
      |     destinationTransportPort     |          16 |     No    |
      | postNAPTdestinationTransportPort |          16 |     No    |
      |       internalAddressRealm       |           8 |     No    |
      |       externalAddressRealm       |           8 |     No    |
      |             natEvent             |           8 |    Yes    |
      +----------------------------------+-------------+-----------+

            Table 6: NAT64 session create/delete event template

5.6.3.  NAT44 BIB create and delete events

   These events will be generated when a NAT44 Bind entry is created or
   deleted.  The following is a template of the event.

         +-----------------------------+-------------+-----------+
         |          Field Name         | Size (bits) | Mandatory |
         +-----------------------------+-------------+-----------+
         |          timeStamp          |          64 |    Yes    |
         |        natInstanceID        |          32 |     No    |
         |     vlanID/ingressVRFID     |          32 |     No    |
         |      sourceIPv4Address      |          32 |    Yes    |
         |   postNATSourceIPv4Address  |          32 |    Yes    |
         |      protocolIdentifier     |           8 |     No    |
         |     sourceTransportPort     |          16 |     No    |
         | postNAPTsourceTransportPort |          16 |     No    |
         |     internalAddressRealm    |           8 |     No    |
         |     externalAddressRealm    |           8 |     No    |
         |           natEvent          |           8 |    Yes    |
         +-----------------------------+-------------+-----------+

              Table 7: NAT44 BIB create/delete event template

5.6.4.  NAT64 BIB create and delete events

   These events will be generated when a NAT64 Bind entry is created or
   deleted.  The following is a template of the event.

         +-----------------------------+-------------+-----------+
         |          Field Name         | Size (bits) | Mandatory |
         +-----------------------------+-------------+-----------+
         |          timeStamp          |          64 |    Yes    |
         |        natInstanceID        |          32 |     No    |
         |     vlanID/ingressVRFID     |          32 |     No    |
         |      sourceIPv6Address      |         128 |    Yes    |
         |   postNATSourceIPv4Address  |          32 |    Yes    |
         |      protocolIdentifier     |           8 |     No    |
         |     sourceTransportPort     |          16 |     No    |
         | postNAPTsourceTransportPort |          16 |     No    |
         |     internalAddressRealm    |           8 |     No    |
         |     externalAddressRealm    |           8 |     No    |
         |           natEvent          |           8 |    Yes    |
         +-----------------------------+-------------+-----------+

              Table 8: NAT64 BIB create/delete event template

5.6.5.  Addresses Exhausted event

   This event will be generated when a NAT device runs out of global
   IPv4 addresses in a given pool of addresses.  Typically, this event
   would mean that the NAT device wont be able to create any new
                                  ^^^^
SD: "won't"

[Senthil] Ok.


   translations until some addresses/ports are freed.  This event SHOULD
   be rate limited as many packets hitting the device at the same time
   will trigger a burst of addresses exhausted events.

   The following is a template of the event.  Note that either the NAT
   pool name or the nat pool identifier should be logged, but not both.

SD: I lack understanding, but I didn't see anything that looked like a NAT =
pool name in the template. Did I miss something?

[Senthil] We decided not to use a string like a pool name instead use a poo=
lID, which is a unique identifier for each pool name. The reason being that=
 the logs could become fairly large
If we have to carry the names and some of the NAT engines implement this in=
 the hardware that lacks the string processing capability.


                +---------------+-------------+-----------+
                |   Field Name  | Size (bits) | Mandatory |
                +---------------+-------------+-----------+
                |   timeStamp   |          64 |    Yes    |
                | natInstanceID |          32 |     No    |
                |    natEvent   |           8 |    Yes    |
                |   natPoolID   |          32 |    Yes    |
                +---------------+-------------+-----------+

                 Table 9: Address Exhausted event template

5.6.6.  Ports Exhausted event

   This event will be generated when a NAT device runs out of ports for
   a global IPv4 address.  Port exhaustion shall be reported per
   protocol (UDP, TCP etc).  This event SHOULD be rate limited as many
   packets hitting the device at the same time will trigger a burst of
   port exhausted events.

   The following is a template of the event.

          +--------------------------+-------------+-----------+
          |        Field Name        | Size (bits) | Mandatory |
          +--------------------------+-------------+-----------+
          |        timeStamp         |          64 |    Yes    |
          |      natInstanceID       |          32 |     No    |
          |         natEvent         |           8 |    Yes    |
          | postNATSourceIPv4Address |          32 |    Yes    |
          |    protocolIdentifier    |           8 |    Yes    |
          +--------------------------+-------------+-----------+

                 Table 10: Ports Exhausted event template

5.6.7.  Quota exceeded events

   This event will be generated when a NAT device cannot allocate
   resources as a result of an administratively defined policy.  The
   quota exceeded event templates are described below
                                                     ^
SD: missing period
[Senthil] Ok.


5.6.7.1.  Maximum session entries exceeded

   The maximum session entries exceeded is generated when the
   administratively configured limit is reached.  The following is the
   template of the event.

               +-----------------+-------------+-----------+
               |    Field Name   | Size (bits) | Mandatory |
               +-----------------+-------------+-----------+
               |    timeStamp    |          64 |    Yes    |
               |  natInstanceID  |          32 |     No    |
               |     natEvent    |           8 |    Yes    |
               |  natLimitEvent  |          32 |    Yes    |
               | configuredLimit |          32 |    Yes    |
               +-----------------+-------------+-----------+

             Table 11: Session Entries Exceeded event template

5.6.7.2.  Maximum BIB entries exceeded

   The maximum BIB entries exceeded is generated when the
   administratively configured limit is reached.  The following is the
   template of the event.

               +-----------------+-------------+-----------+
               |    Field Name   | Size (bits) | Mandatory |
               +-----------------+-------------+-----------+
               |    timeStamp    |          64 |    Yes    |
               |  natInstanceID  |          32 |     No    |
               |     natEvent    |           8 |    Yes    |
               |  natLimitEvent  |          32 |    Yes    |
               | configuredLimit |          32 |    Yes    |
               +-----------------+-------------+-----------+

               Table 12: BIB Entries Exceeded event template

5.6.7.3.  Maximum entries per user exceeded

   This event is generated when a single user reaches the
   administratively configured limit.  The following is the template of
   the event.

           +---------------------+-------------+---------------+
           |      Field Name     | Size (bits) |   Mandatory   |
           +---------------------+-------------+---------------+
           |      timeStamp      |          64 |      Yes      |
           |    natInstanceID    |          32 |       No      |
           |       natEvent      |           8 |      Yes      |
           |    natLimitEvent    |          32 |      Yes      |
           |   configuredLimit   |          32 |      Yes      |
           | vlanID/ingressVRFID |          32 |       No      |
           |  sourceIPv4 address |          32 | Yes for NAT44 |
           |  sourceIPv6 address |         128 | Yes for NAT64 |
           +---------------------+-------------+---------------+

            Table 13: Per-user Entries Exceeded event template

5.6.7.4.  Maximum active host or subscribers exceeded

   This event is generated when the number of allowed hosts or
   subscribers reaches the administratively configured limit.  The
   following is the template of the event.

               +-----------------+-------------+-----------+
               |    Field Name   | Size (bits) | Mandatory |
               +-----------------+-------------+-----------+
               |    timeStamp    |          64 |    Yes    |
               |  natInstanceID  |          32 |     No    |
               |     natEvent    |           8 |    Yes    |
               |  natLimitEvent  |          32 |    Yes    |
               | configuredLimit |          32 |    Yes    |
               +-----------------+-------------+-----------+

        Table 14: Maximum hosts/subscribers Exceeded event template

5.6.7.5.  Maximum fragments pending reassembly exceeded

   This event is generated when the number of fragments pending
   reassembly reaches the administratively configured limit.  The
   following is the template of the event.

          +----------------------+-------------+---------------+
          |      Field Name      | Size (bits) |   Mandatory   |
          +----------------------+-------------+---------------+
          |      timeStamp       |          64 |      Yes      |
          |    natInstanceID     |          32 |       No      |
          |       natEvent       |           8 |      Yes      |
          |    natLimitEvent     |          32 |      Yes      |
          |   configuredLimit    |          32 |      Yes      |
          | internalAddressRealm |           8 |      Yes      |
          | vlanID/ingressVRFID  |          32 |       No      |
          |  sourceIPv4 address  |          32 | Yes for NAT44 |
          |  sourceIPv6 address  |         128 | Yes for NAT64 |
          +----------------------+-------------+---------------+

       Table 15: Maximum fragments pending reassembly Exceeded event
                                 template

5.6.8.  Threshold reached events

   This event will be generated when a NAT device reaches a operator
   configured threshold when allocating resources.  The threshold
   reached events are described in the section above.  The following is
   a template of the individual events.

5.6.8.1.  Address pool high or low threshold reached

   This event is generated when the high or low threshold is reached for
   the address pool.  The template is the same for both high and low
   threshold events

              +-------------------+-------------+-----------+
              |     Field Name    | Size (bits) | Mandatory |
              +-------------------+-------------+-----------+
              |     timeStamp     |          64 |    Yes    |
              |   natInstanceID   |          32 |     No    |
              |      natEvent     |           8 |    Yes    |
              | natThresholdEvent |          32 |    Yes    |
              |     natPoolID     |          32 |    Yes    |
              |  configuredLimit  |          32 |    Yes    |
              +-------------------+-------------+-----------+

     Table 16: Address pool high/low threshold reached event template

5.6.8.2.  Address and port high threshold reached

   This event is generated when the high threshold is reached for the
   address pool and ports.

              +-------------------+-------------+-----------+
              |     Field Name    | Size (bits) | Mandatory |
              +-------------------+-------------+-----------+
              |     timeStamp     |          64 |    Yes    |
              |   natInstanceID   |          32 |     No    |
              |      natEvent     |           8 |    Yes    |
              | natThresholdEvent |          32 |    Yes    |
              |  configuredLimit  |          32 |    Yes    |
              +-------------------+-------------+-----------+

       Table 17: Address port high threshold reached event template

5.6.8.3.  Per-user Address and port high threshold reached

   This event is generated when the high threshold is reached for the
   per-user address pool and ports.

           +---------------------+-------------+---------------+
           |      Field Name     | Size (bits) |   Mandatory   |
           +---------------------+-------------+---------------+
           |      timeStamp      |          64 |      Yes      |
           |    natInstanceID    |          32 |       No      |
           |       natEvent      |           8 |      Yes      |
           |  natThresholdEvent  |          32 |      Yes      |
           |   configuredLimit   |          32 |      Yes      |
           | vlanID/ingressVRFID |          32 |       No      |
           |  sourceIPv4 address |          32 | Yes for NAT44 |
           |  sourceIPv6 address |         128 | Yes for NAT64 |
           +---------------------+-------------+---------------+

   Table 18: Per-user Address port high threshold reached event template

5.6.8.4.  Global Address mapping high threshold reached

   This event is generated when the high is reached for the per-user
   address pool and ports.  This is generated only by NAT devices that
   use a address pooling behavior of paired.

             +---------------------+-------------+-----------+
             |      Field Name     | Size (bits) | Mandatory |
             +---------------------+-------------+-----------+
             |      timeStamp      |          64 |    Yes    |
             |    natInstanceID    |          32 |     No    |
             |       natEvent      |           8 |    Yes    |
             |  natThresholdEvent  |          32 |    Yes    |
             |   configuredLimit   |          32 |    Yes    |
             | vlanID/ingressVRFID |          32 |     No    |
             +---------------------+-------------+-----------+

       Table 19: Global Address mapping high threshold reached event
                                 template

5.6.9.  Address binding create and delete events

   These events will be generated when a NAT device binds a local
   address with a global address and when the global address is freed.
   This binding event happens when the first packet of the first flow
   from a host in the private realm.

     +--------------------------------+-------------+---------------+
     |           Field Name           | Size (bits) |   Mandatory   |
     +--------------------------------+-------------+---------------+
     |           timeStamp            |          64 |      Yes      |
     |         natInstanceID          |          32 |       No      |
     |            natEvent            |           8 |      Yes      |
     |       sourceIPv4 address       |          32 | Yes for NAT44 |
     |       sourceIPv6 address       |         128 | Yes for NAT64 |
     | Translated Source IPv4 Address |          32 |      Yes      |
     +--------------------------------+-------------+---------------+

                  Table 20: NAT Address Binding template

5.6.10.  Port block allocation and de-allocation

   This event will be generated when a NAT device allocates/de-allocates
   ports in a bulk fashion, as opposed to allocating a port on a per
   flow basis.

   portRangeStart represents the starting value of the range.

   portRangeEnd represents the ending value of the range.

   NAT devices would do this in order to reduce logs and potentially to
   limit the number of connections a subscriber is allowed to use.  In
   the following Port Block allocation template, the portRangeStart and
   portRangeEnd must be specified.


Sivakumar & Penno        Expires August 15, 2014               [Page 17]

Internet-Draft          IPFIX IEs for NAT logging          February 2014

   It is up to the implementation to choose to consolidate log records
   in case two consecutive port ranges for the same user are allocated
   or freed.

     +--------------------------------+-------------+---------------+
     |           Field Name           | Size (bits) |   Mandatory   |
     +--------------------------------+-------------+---------------+
     |           timeStamp            |          64 |      Yes      |
     |         natInstanceID          |          32 |       No      |
     |            natEvent            |           8 |      Yes      |
     |       sourceIPv4 address       |          32 | Yes for NAT44 |
     |       sourceIPv6 address       |         128 | Yes for NAT64 |
     | Translated Source IPv4 Address |          32 |      Yes      |
     |         portRangeStart         |          16 |      Yes      |
     |          portRangeEnd          |          16 |       No      |
     +--------------------------------+-------------+---------------+

            Table 21: NAT Port Block Allocation event template

6.  Encoding

6.1.  IPFIX

   This document uses IPFIX as the encoding mechanism to describe the
   logging of NAT events.  However, the information that should be
   logged SHOULD be the same irrespective of what kind of encoding
   scheme is used.  IPFIX is chosen because is it an IETF standard that
   meets all the needs for a reliable logging mechanism.  IPFIX provides
   the flexibility to the logging device to define the data sets that it
   is logging.  The IEs specified for logging MUST be the same
   irrespective of the encoding mechanism used.

7.  Acknowledgements

   Thanks to Dan Wing, Selvi Shanmugam, Mohamed Boucadir, Jacni Qin
   Ramji Vaithianathan, Simon Perreault, Jean-Francois Tremblay, Paul
   Aitken and Julia Renouard for their review and comments.

8.  IANA Considerations

   The following information elements are requested from IANA IPFIX
   registry.

   natInstanceId

   externalAddressRealm

   natLimitEvent

9.  Management Considerations

   This section considers requirements for management of the log system
   to support logging of the events described above.  It first covers
   requirements applicable to log management in general.  Any additional
   standardization required to fullfil these requirements is out of
   scope of the present document.  Some management considerations is
   covered in [I-D.behave-syslog-nat-logging].  This document covers the
   additional considerations.

9.1.  Ability to collect events from multiple NAT devices

   An IPFIX collector should be able to collect events from multiple NAT
   devices and be able to decipher events based on the sourceID in the
   IPFIX header.

9.2.  Ability to suppress events

   The exhaustion events can be overwhelming during traffic bursts and
   hence should be handled by the NAT devices to rate limit them before
   sending them to the collectors.  For eg. when the port exhaustion
   happens during bursty conditions, instead of sending a port
   exhaustion event for every packet, the exhaustion events should be
   rate limited by the NAT device.

10.  Security Considerations

   None.

11.  References

11.1.  Normative References

   [RFC2119]  Bradner, S., "Key words for use in RFCs to Indicate
              Requirement Levels", BCP 14, RFC 2119, March 1997.

   [RFC2663]  Srisuresh, P. and M. Holdrege, "IP Network Address
              Translator (NAT) Terminology and Considerations", RFC
              2663, August 1999.

   [RFC4787]  Audet, F. and C. Jennings, "Network Address Translation
              (NAT) Behavioral Requirements for Unicast UDP", BCP 127,
              RFC 4787, January 2007.

   [RFC5382]  Guha, S., Biswas, K., Ford, B., Sivakumar, S., and P.
              Srisuresh, "NAT Behavioral Requirements for TCP", BCP 142,
              RFC 5382, October 2008.

   [RFC6146]  Bagnulo, M., Matthews, P., and I. van Beijnum, "Stateful
              NAT64: Network Address and Protocol Translation from IPv6
              Clients to IPv4 Servers", RFC 6146, April 2011.

   [RFC6302]  Durand, A., Gashinsky, I., Lee, D., and S. Sheppard,
              "Logging Recommendations for Internet-Facing Servers", BCP
              162, RFC 6302, June 2011.

   [RFC6888]  Perreault, S., Yamagata, I., Miyakawa, S., Nakagawa, A.,
              and H. Ashida, "Common Requirements for Carrier-Grade NATs
              (CGNs)", BCP 127, RFC 6888, April 2013.

11.2.  Informative References

   [I-D.ietf-behave-syslog-nat-logging]
              Chen, Z., Zhou, C., Tsou, T., and T. Taylor, "Syslog
              Format for NAT Logging", draft-ietf-behave-syslog-nat-
              logging-06 (work in progress), January 2014.

   [IPFIX-IANA]
              IANA, "IPFIX Information Elements registry",
              <http://www.iana.org/assignments/ipfix><http://www.iana.org/a=
ssignments/ipfix>.

   [RFC5101bis]
              Claise, B. and B. Trammel, "Specification of the IP Flow
              Information eXport (IPFIX) Protocol for the Exchange of
              Flow Information", July 2013.

   [RFC5102bis]
              Claise, B. and B. Trammel, "Information Model for IP Flow
              Information eXport (IPFIX)", February 2013.

   [RFC5470]  Sadasivan, G., Brownlee, N., Claise, B., and J. Quittek,
              "Architecture for IP Flow Information Export", RFC 5470,
              March 2009.

Authors' Addresses

   Senthil Sivakumar
   Cisco Systems
   7100-8 Kit Creek Road
   Research Triangle Park, North Carolina  27709
   USA

   Phone: +1 919 392 5158

   Renaldo Penno
   Cisco Systems
   170 W Tasman Drive
   San Jose, California  95035
   USA

   Email: repenno@cisco.com<mailto:repenno@cisco.com>






















Sivakumar & Penno        Expires August 15, 2014               [Page 21]

--_000_CF89605B1009FBssenthilciscocom_
Content-Type: text/html; charset="Windows-1252"
Content-ID: <51136474D3C20D47867D8BCAD7754666@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-lin=
e-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-fami=
ly: Calibri, sans-serif; ">
<div>Hi Spencer,&nbsp;</div>
<div>Thanks for the thorough review.&nbsp;</div>
<div>Please see inline for [Senthil]. If you agree, I will submit another v=
ersion fixing all the issues raised and agreed upon. I will wait for your r=
esponse.</div>
<div><br>
</div>
<div>Thanks</div>
<div>Senthil</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div style=3D"font-family:Calibri; font-size:11pt; text-align:left; color:b=
lack; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM:=
 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;=
 BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style=3D"font-weight:bold">From: </span>Spencer Dawkins &lt;<a href=
=3D"mailto:spencerdawkins.ietf@gmail.com">spencerdawkins.ietf@gmail.com</a>=
&gt;<br>
<span style=3D"font-weight:bold">Date: </span>Thursday, May 1, 2014 4:25 PM=
<br>
<span style=3D"font-weight:bold">To: </span>&quot;<a href=3D"mailto:draft-i=
etf-behave-ipfix-nat-logging@tools.ietf.org">draft-ietf-behave-ipfix-nat-lo=
gging@tools.ietf.org</a>&quot; &lt;<a href=3D"mailto:draft-ietf-behave-ipfi=
x-nat-logging@tools.ietf.org">draft-ietf-behave-ipfix-nat-logging@tools.iet=
f.org</a>&gt;<br>
<span style=3D"font-weight:bold">Cc: </span>&quot;<a href=3D"mailto:behave@=
ietf.org">behave@ietf.org</a>&quot; &lt;<a href=3D"mailto:behave@ietf.org">=
behave@ietf.org</a>&gt;<br>
<span style=3D"font-weight:bold">Subject: </span>AD Evaluation of draft-iet=
f-behave-ipfix-nat-logging-03<br>
<span style=3D"font-weight:bold">Resent-From: </span>&lt;<a href=3D"mailto:=
draft-alias-bounces@tools.ietf.org">draft-alias-bounces@tools.ietf.org</a>&=
gt;<br>
<span style=3D"font-weight:bold">Resent-To: </span>&lt;<a href=3D"mailto:re=
penno@cisco.com">repenno@cisco.com</a>&gt;, Senthil Sivakumar &lt;<a href=
=3D"mailto:ssenthil@cisco.com">ssenthil@cisco.com</a>&gt;<br>
<span style=3D"font-weight:bold">Resent-Date: </span>Thursday, May 1, 2014 =
4:26 PM<br>
</div>
<div><br>
</div>
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace">Dear draft-ietf-behave-ipfix-nat-logging Authors,<br>
<br>
I've completed my AD evaluation for this draft. I found some things I'd lik=
e to see changed before proceeding, but most are editorial. Please take a l=
ook, and let me know what you think.<br>
<br>
My notes follow ... you should be able to find my questions and comments by=
 searching for &quot;SD:&quot;.<br>
<br>
Thanks,<br>
<br>
Spencer<br>
<br>
In the Abstract<br>
<br>
&nbsp;&nbsp; NAT devices are required to log events like creation and delet=
ion of<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^<br>
SD: Is this required, like, legally required, or ? Is it more like &quot;Op=
erators need NAT devices to log events ...&quot;?</font></div>
</div>
</span>
<div>[Senthil] : It is the later, the network operators require the NAT dev=
ices to be able to log events.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp; translations and information about the resources it is managin=
g.&nbsp; The<br>
&nbsp;&nbsp; logs are required in many cases to identify an attacker or a h=
ost<br>
&nbsp;&nbsp; that was used to launch malicious attacks and/or for various o=
ther<br>
&nbsp;&nbsp; purposes of accounting.&nbsp; Since there is no standard way o=
f logging<br>
&nbsp;&nbsp; this information, different NAT devices behave differently and=
 hence<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^<br>
SD: Is this &quot;different NAT devices log this information differently&qu=
ot;? </font></div>
</div>
</span>
<div>[Senthil] Correct, as the sentence says, &quot;Since there is no stand=
ard way=85&quot;, each NAT device logs information in its own proprietary f=
ormat.</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp; it is difficult to expect a consistent behavior.&nbsp; The lac=
k of a<br>
&nbsp;&nbsp; consistent way makes it difficult to write the collector appli=
cations<br>
&nbsp;&nbsp; that would receive this data and process it to present useful<=
br>
&nbsp;&nbsp; information.&nbsp; This document describes the information tha=
t is<br>
&nbsp;&nbsp; required to be logged by the NAT devices.<br>
&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^^^^ <br>
SD: Same as previous question - is this &quot;logged by&quot;?</font></div>
</div>
</span>
<div><br>
</div>
<div>[Senthil] If a NAT device is logging events, these are the requirement=
s that a NAT device should adhere to.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
2.&nbsp; Introduction<br>
<br>
&nbsp;&nbsp; The IPFIX Protocol [RFC5101bis] defines a generic push mechani=
sm for<br>
&nbsp;&nbsp; exporting information and events.&nbsp; The IPFIX Information =
Model<br>
&nbsp;&nbsp; [IPFIX-IANA] defines a set of standard Information Elements (I=
Es)<br>
&nbsp;&nbsp; which can be carried by the IPFIX protocol.&nbsp; This documen=
t details<br>
&nbsp;&nbsp; the IPFIX Information Elements(IEs) that are required for logg=
ing by<br>
&nbsp;&nbsp; a NAT device.&nbsp; The document will specify the format of th=
e IE's that<br>
&nbsp;&nbsp; are required to be logged by the NAT device and all the option=
al<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^<br>
SD: Now that we're in the document body, if this is required, shouldn't the=
re be a reference to where the requirements are stated?</font></div>
</div>
</span>
<div>[Senthil] This is the document that is specifying those requirements. =
Do you have any other suggestions of wording instead of &quot;required by&q=
uot;, would it be fine if I change the sentence from</div>
<div>&quot;required to be logged&quot; to &quot;SHOULD be logged&quot;?&nbs=
p;</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
&nbsp;&nbsp; fields.&nbsp; The fields specified in this document are gleane=
d from<br>
&nbsp;&nbsp; [RFC4787] and [RFC5382].<br>
<br>
&nbsp;&nbsp; Test [3GPP]<br>
&nbsp;&nbsp; ^^^^^^^^^^^<br>
SD: Is something missing here? It's just the word &quot;Test&quot; and a re=
ference.</font></div>
</div>
</span>
<div>[Senthil] Agree. I will remove this.</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp; This document and [I-D.behave-syslog-nat-logging] are provided=
 in<br>
&nbsp;&nbsp; order to standardize the events and parameters to be recorded,=
 using<br>
&nbsp;&nbsp; IPFIX [RFC5101bis] and SYSLOG [RFC5424]respectively.<br>
<br>
3.&nbsp; Scope<br>
<br>
&nbsp;&nbsp; This document provides the information model to be used for lo=
gging<br>
&nbsp;&nbsp; the NAT devices including Carrier Grade NAT (CGN) events.&nbsp=
; This<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^<=
br>
SD: This sentence seems somewhat turned around - &quot;logging events&quot;=
, not &quot;logging the NAT devices&quot;.</font></div>
</div>
</span>
<div>[Senthil] Agree, I will change this to &quot;logging the NAT events&qu=
ot;.&nbsp;</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp; document focuses exclusively on the specification of IPFIX IE'=
s.<br>
&nbsp;&nbsp; This document does not provide guidance on the transport proto=
col<br>
&nbsp;&nbsp; like TCP, UDP or SCTP that is to be used to log NAT events.&nb=
sp; The log<br>
&nbsp;&nbsp; events SHOULD NOT be lost but the choice of the actual transpo=
rt<br>
&nbsp;&nbsp; protocol is beyond the scope of this document.<br>
<br>
SD: I'm not understanding why this last sentence is needed, especially with=
 a normative requirement for what you do when you are doing something outsi=
de the scope of the document ...</font></div>
</div>
</span>
<div>[Senthil] Are you objecting to the second part of the last sentence &q=
uot;the choice of actual transport=85&quot;, I think the requirement is tha=
t the LOG events should not be lost is valid.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
&nbsp;&nbsp; The existing IANA IPFIX IEs registry [IPFIX-IANA] already has<=
br>
&nbsp;&nbsp; assignments for many NAT logging events.&nbsp; For convenience=
, this<br>
&nbsp;&nbsp; document uses those same IEs.&nbsp; However, as stated earlier=
, this<br>
&nbsp;&nbsp; document is not defining IPFIX or NetFlow v9 as the framework =
for<br>
&nbsp;&nbsp; logging.&nbsp; Rather, the information contained in these elem=
ents is<br>
<br>
SD: I got lost on &quot;these elements&quot; - is that &quot;the elements i=
n the existing registry&quot;</font></div>
</div>
</span>
<div>[Senthil] Yes. How about &quot;Rather, the information elements as def=
ined in the IPFIX-IANA registry is within the scope of this document&quot;?=
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp; within the scope of this document.<br>
<br>
&nbsp;&nbsp; This document assumes that the NAT device will use the existin=
g IPFIX<br>
&nbsp;&nbsp; framework to send the log events to the collector.&nbsp; This =
would mean<br>
&nbsp;&nbsp; that the NAT device will specify the template that it is going=
 to use<br>
&nbsp;&nbsp; for each of the events.&nbsp; The templates can be of varying =
length and<br>
&nbsp;&nbsp; there could be multiple templates that a NAT device could use =
to log<br>
&nbsp;&nbsp; the events.<br>
<br>
&nbsp;&nbsp; The implementation details of the collector application is bey=
ond the<br>
&nbsp;&nbsp; scope of this document.<br>
<br>
&nbsp;&nbsp; The optimization of logging the NAT events are left to the<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^<br>
&nbsp;&nbsp; implementation and are beyond the scope of this document.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^<br>
SD: It's a nit, but those &quot;are&quot;s should be &quot;is&quot;s.</font=
></div>
</div>
</span>
<div>[Senthil] Ok.</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
4.&nbsp; Applicability<br>
<br>
&nbsp;&nbsp; NAT logging based on IPFIX uses binary encoding and hence is v=
ery<br>
&nbsp;&nbsp; efficient.&nbsp; IPFIX based logging is recommended for enviro=
nments where<br>
&nbsp;&nbsp; a high volume of logging is required, for example, where per-f=
low<br>
&nbsp;&nbsp; logging is needed.&nbsp; However, IPFIX based logging requires=
 a collector<br>
&nbsp;&nbsp; that processes the binary data and requires a network manageme=
nt<br>
&nbsp;&nbsp; application that converts this binary data to a human readable=
<br>
&nbsp;&nbsp; format.<br>
<br>
5.&nbsp; Event based logging<br>
<br>
&nbsp;&nbsp; An event in a NAT device can be viewed as a happening as it re=
lates<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^<br>
SD: Is this &quot;a state transition&quot;? I found &quot;a happening&quot;=
 somewhat odd.</font></div>
</div>
</span>
<div>[Senthil] Yes, I can rephrase this as &quot;viewed as a state transiti=
on as it relates to&quot; or &quot;viewed as an action as it relates to&quo=
t;, if that is ok.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp; to the management of NAT resources.&nbsp; The creation and del=
etion of NAT<br>
&nbsp;&nbsp; sessions and bindings are examples of events as it results in =
the<br>
&nbsp;&nbsp; resources (addresses and ports) being allocated or freed.&nbsp=
; The events<br>
&nbsp;&nbsp; can happen either through the processing of data packets flowi=
ng<br>
&nbsp;&nbsp; through the NAT device or through an external entity installin=
g<br>
&nbsp;&nbsp; policies on the NAT router or as a result of an asynchronous e=
vent<br>
&nbsp;&nbsp; like a timer.&nbsp; The list of events are provided in Section=
 4.1.&nbsp; Each<br>
&nbsp;&nbsp; of these events SHOULD be logged, unless they are administrati=
vely<br>
&nbsp;&nbsp; prohibited.&nbsp; A NAT device MAY log these events to multipl=
e collectors<br>
&nbsp;&nbsp; if redundancy is required.&nbsp; The network administrator wil=
l specify<br>
&nbsp;&nbsp; the collectors to which the log records are to be sent.<br>
<br>
&nbsp;&nbsp; A collector may receive NAT events from multiple CGN devices a=
nd<br>
&nbsp;&nbsp; should be able to distinguish between the devices.&nbsp; Each =
CGN device<br>
&nbsp;&nbsp; ^^^^^^<br>
SD: I'm not sure why this isn't a SHOULD, or even a MUST.<br>
<br>
&nbsp;&nbsp; should have a unique source ID to identify themselves.&nbsp; T=
he source ID<br>
&nbsp;&nbsp; ^^^^^^<br>
SD: Again, I'm not sure why this isn't a SHOULD, or even a MUST.</font></di=
v>
</div>
</span>
<div><br>
</div>
<div>[Senthil] Well, this is NOT a statement for a NAT device, instead it i=
s a collector that some application writer will&nbsp;</div>
<div>develop.&nbsp;</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp; is part of the IPFIX template and data exchange.<br>
<br>
&nbsp;&nbsp; Prior to logging any events, the NAT device MUST send the temp=
late of<br>
&nbsp;&nbsp; the record to the collector to advertise the format of the dat=
a<br>
&nbsp;&nbsp; record that it is using to send the events.&nbsp; The template=
s can be<br>
&nbsp;&nbsp; exchanged as frequently as required given the reliability of t=
he<br>
&nbsp;&nbsp; connection.&nbsp; There SHOULD be a configurable timer for con=
trolling the<br>
&nbsp;&nbsp; template refresh.&nbsp; NAT device SHOULD combine as many even=
ts as<br>
&nbsp;&nbsp; possible in a single packet to effectively utilize the network=
<br>
&nbsp;&nbsp; bandwidth.<br>
<br>
5.1.&nbsp; Logging of destination information<br>
<br>
&nbsp;&nbsp; Logging of destination information in a NAT event has been dis=
cussed<br>
&nbsp;&nbsp; in [RFC6302] and [RFC6888].&nbsp; Logging of destination infor=
mation<br>
&nbsp;&nbsp; increases the size of each record and increases the need for s=
torage<br>
&nbsp;&nbsp; considerably.&nbsp; It increases the number of log events gene=
rated<br>
&nbsp;&nbsp; because when the same user connects to a different destination=
, it<br>
&nbsp;&nbsp; results in a log record per destination address.&nbsp; Logging=
 of<br>
&nbsp;&nbsp; destination information also results in the loss of privacy an=
d hence<br>
&nbsp;&nbsp; should be done with caution.&nbsp; However, this draft provide=
s the<br>
&nbsp;&nbsp; necessary fields to log the destination information in cases w=
here<br>
&nbsp;&nbsp; they are required to be logged.<br>
<br>
5.2.&nbsp; Information Elements<br>
<br>
&nbsp;&nbsp; The templates could contain a subset of the Information Elemen=
ts(IEs)<br>
&nbsp;&nbsp; shown in Table 1 depending upon the event being logged.&nbsp; =
For example<br>
&nbsp;&nbsp; a NAT44 session creation template record will contain,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^<br>
SD: Is this the only possible NAT44 template? If so, fine, but if not, perh=
aps &quot;could contain&quot;, or &quot;typically contains&quot;?</font></d=
iv>
</div>
</span>
<div><br>
</div>
<div>[Senthil] Yes, this is all the information that a NAT44 need to export=
 as it is the least common denominator.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp; {sourceIPv4Adress, postNATSourceIPv4Address, destinationIpv4Ad=
dress,<br>
&nbsp;&nbsp; postNATDestinationIPv4Address, sourceTransportPort,<br>
&nbsp;&nbsp; postNAPTSourceTransportPort, destinationTransportPort,<br>
&nbsp;&nbsp; postNAPTDestTransportPort, internalAddressRealm, natEvent, tim=
eStamp}<br>
<br>
&nbsp;&nbsp; An example of the actual event data record is shown below - in=
 a<br>
&nbsp;&nbsp; readable form<br>
<br>
&nbsp;&nbsp; {192.168.16.1, 201.1.1.100, 207.85.231.104, 207.85.231.104, 14=
800,<br>
&nbsp;&nbsp; 1024, 80, 80, 0, 1, 09:20:10:789}<br>
<br>
&nbsp;&nbsp; A single NAT device could be exporting multiple templates and =
the<br>
&nbsp;&nbsp; collector should support receiving multiple templates from the=
 same<br>
&nbsp;&nbsp; source.observationTimeMilliseconds<br>
<br>
&nbsp;&nbsp; The following is the table of all the IE's that a CGN device w=
ould<br>
&nbsp;&nbsp; need to export the events.&nbsp; The formats of the IE's and t=
he IPFIX IDs<br>
&nbsp;&nbsp; are listed below.<br>
<br>
SD: I noticed that some IEs below have a name that matches <a class=3D"moz-=
txt-link-freetext" href=3D"http://www.iana.org/assignments/ipfix/ipfix.xhtm=
l#ipfix-information-elements">
http://www.iana.org/assignments/ipfix/ipfix.xhtml#ipfix-information-element=
s</a> for the same IPFIX ID number, but others do not (&quot;timeStamp&quot=
; here doesn't match &quot;observationTimeMilliseconds&quot;, but both are =
IPFIX ID 323, aren't they?) Is there a reason to use
 names that don't match the IANA registry?</font></div>
</div>
</span>
<div><br>
</div>
<div>[Senthil] Good question, in case of timeStamp, I was looking for somet=
hing that already existed in the IPFIX registry rather than asking for a ne=
w one. However, the terminology of &quot;observationTimeMilliseconds&quot; =
is not the terminology that we use in the
 NAT drafts/rfc's. So I am open to suggestions here. I can clarify in the d=
escription that is called observationTimeMilliSeconds&quot;. The other fiel=
d is internalAddressRealm and externalAddresRealm, this is the terminology =
that we used in NAT MIB, syslog and other
 documents. However, when we defined the IPFIX IE, we didn=92t stick to the=
 same terminology, so I don=92t know if I can go and ask the IPFIX IANA to =
change the name. Again I am open to suggestions, the dillema is whether I s=
hould stick to the existing IPFIX IANA
 terminology or the behave documents terminology.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp; &#43;----------------------------------&#43;--------&#43;-----=
--&#43;---------------&#43;<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp; |&nbsp;&nbsp; Size |&nbsp; IANA |&nbsp; Description&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | (bits) | I=
PFIX |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; ID |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; &#43;----------------------------------&#43;--------&#43;-----=
--&#43;---------------&#43;<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp; 323 |&nbsp; System =
Time&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; when the&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp; event&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; occured.&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natIns=
tanceId&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; TBD |&nbsp; NAT Instance |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp; Identifier&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; vlanID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp=
; 58 |&nbsp;&nbsp; VLAN ID in&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; case of&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; overlapping&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; networks&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 234 |&nbsp;&nbsp; VRF ID in&nbsp;&=
nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; case of&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; overlapping&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; networks&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv4Address&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 3=
2 |&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp; Source IPv4&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; Address&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv4Address&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 225 |&nbsp;&nbsp; T=
ranslated&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; Source IPv4&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; Address&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; protocolIdentifier=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
8 |&nbsp;&nbsp;&nbsp;&nbsp; 4 |&nbsp;&nbsp; Transport&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; protocol&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceTransportPort&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&=
nbsp;&nbsp;&nbsp; 7 |&nbsp; Source Port&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp; postNAPTsourceTransportPort&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp; 227 |&nbsp;&nbsp; Translated&nbsp;=
 |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; Source port&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationIPv4Address&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; 12 =
|&nbsp; Destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; IPv4 Address |<br>
&nbsp;&nbsp; |&nbsp; postNATDestinationIPv4Address&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 226 |&nbsp;&nbsp; Translated&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp; IPv4&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; address&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; destinationTransportPort&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; 11 |&nbsp; De=
stination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp; port&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; | postNAPTdestinationTransportPort |&nbsp;&nbsp;&nbsp;&nbsp; 1=
6 |&nbsp;&nbsp; 228 |&nbsp;&nbsp; Translated&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; Destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp; port&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv6Address&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 2=
7 |&nbsp;&nbsp; 128 |&nbsp; Source IPv6&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; address&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationIPv6Address&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp; 28 |&nbs=
p; Destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; IPv6 address |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv6Address&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp; 281 |&nbsp;&nbsp; Transl=
ated&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; source IPv6&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; addresss&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp; postNATDestinationIPv6Address&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp; 128 |&nbsp;&nbsp; 282 |&nbsp;&nbsp; Translated&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; Destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; IPv6 address |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; internalAddressRealm&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&=
nbsp; 229 |&nbsp;&nbsp;&nbsp;&nbsp; Source&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Add=
ress Realm |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; externalAddressRealm&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&=
nbsp; TBD |&nbsp; Destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Add=
ress Realm |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp; 230 | Typ=
e of Event |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; portRa=
ngeStart&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp; 16 |&nbsp;&nbsp; 361 |&nbsp;&nbsp; Allocated&nbsp;&nbsp; |<br=
>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp; port block&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp; start&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
portRangeEnd&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp; 362 |&nbsp;&nbsp; Allocated&nbsp;&=
nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp; Port block&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp; end&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; natPoolID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 283 |&nbsp;&nbsp;&n=
bsp; NAT pool&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp; Identifier&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natLim=
itEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; TBD |&nbsp; Limit event&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp; identifier&nbsp; |<br>
&nbsp;&nbsp; &#43;----------------------------------&#43;--------&#43;-----=
--&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 1: Template forma=
t Table<br>
<br>
5.3.&nbsp; Definition of NAT Events<br>
<br>
&nbsp;&nbsp; The following are the list of NAT events and the proposed even=
t<br>
&nbsp;&nbsp; values.&nbsp; The list can be expanded in the future as necess=
ary.&nbsp; The<br>
&nbsp;&nbsp; data record will have the corresponding natEvent value to iden=
tify<br>
&nbsp;&nbsp; the event that is being logged.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------&#43;-----=
---&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p; Event Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Values |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------&#43;-----=
---&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT44 Session create&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT44 Session delete&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | NAT Addresses exhausted&nbsp; |&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp; 3 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT64 Session create&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT64 Session delete&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 5 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT44 BIB creat=
e&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 6 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT44 BIB delet=
e&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 7 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT64 BIB creat=
e&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT64 BIB delet=
e&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 9 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT ports exhausted&nbsp;&n=
bsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 10 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Quota exc=
eeded&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 11 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Address binding create&nbsp; |&nb=
sp;&nbsp;&nbsp;&nbsp; 12 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Address binding delete&nbsp; |&nb=
sp;&nbsp;&nbsp;&nbsp; 13 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Port block allocation&nbsp;&nbsp;=
 |&nbsp;&nbsp;&nbsp;&nbsp; 14 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Port block de-allocation |&nbsp;&nbsp;&=
nbsp;&nbsp; 15 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; Threshold reached&nbs=
p;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------&#43;-----=
---&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 2: NA=
T Event ID table<br>
<br>
5.4.&nbsp; Quota exceeded Event types<br>
<br>
&nbsp;&nbsp; The following table shows the sub event types for the Quota ex=
ceeded<br>
&nbsp;&nbsp; or limits reached event.&nbsp; The events that can be reported=
 are the<br>
&nbsp;&nbsp; Maximum session entries limit reached, Maximum BIB entries lim=
it<br>
&nbsp;&nbsp; reached, Maximum session/BIB entries per user limit reached an=
d<br>
&nbsp;&nbsp; maximum subscribers or hosts limit reached.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---=
------------------------------------&#43;--------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Quota Exceeded Event Name&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp; | Values |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---=
------------------------------------&#43;--------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Maximum Session entries&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Maximum BIB entries&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; 2 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Maximum entries per user&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; =
Maximum active hosts or subscribers&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4=
 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; =
Maximum fragments pending reassembly |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 5 |<br=
>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---=
------------------------------------&#43;--------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 3: Quota Exceeded event table=
<br>
<br>
5.5.&nbsp; Threshold reached Event types<br>
<br>
&nbsp;&nbsp; The following table shows the sub event types for the threshol=
d<br>
&nbsp;&nbsp; reached event.&nbsp; The administrator can configure the thres=
holds and<br>
&nbsp;&nbsp; whenever the threshold is reached or exceeded, the correspondi=
ng<br>
&nbsp;&nbsp; events are generated.<br>
<br>
&nbsp;&nbsp; The address pool high threshold event will be reported when th=
e<br>
&nbsp;&nbsp; address pool reaches a high water mark as defined by the opera=
tor.<br>
&nbsp;&nbsp; This will sever as an indication that the operator might have =
to add<br>
&nbsp;&nbsp; more addresses to the pool or an indication that the subsequen=
t users<br>
&nbsp;&nbsp; may be denied NAT translation mappings.<br>
<br>
&nbsp;&nbsp; The address and port mapping high threshold event is generated=
, when<br>
&nbsp;&nbsp; the number of ports in the configured address pool has reached=
 a<br>
&nbsp;&nbsp; configured threshold.<br>
<br>
&nbsp;&nbsp; The per-user address and port mapping high threshold is genera=
ted<br>
&nbsp;&nbsp; when a single user uses more address and port mapping than a<b=
r>
&nbsp;&nbsp; configured threshold.<br>
<br>
&nbsp;&nbsp; &#43;---------------------------------------------------------=
&#43;--------&#43;<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; Threshold Exceeded Event Name&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Values |<br>
&nbsp;&nbsp; &#43;---------------------------------------------------------=
&#43;--------&#43;<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; Address pool high threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1 |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; Address pool low threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2 |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Address and port mapping high =
threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p; 3 |<br>
&nbsp;&nbsp; |&nbsp; Address and port mapping per user high threshold event=
 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4 |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Global Address mapping h=
igh threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; 5 |<br>
&nbsp;&nbsp; &#43;---------------------------------------------------------=
&#43;--------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 4: Threshold even=
t table<br>
<br>
5.6.&nbsp; Templates for NAT Events<br>
<br>
&nbsp;&nbsp; The following is the template of events that will have to logg=
ed.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^=
^^<br>
<br>
SD: I think this is a nit, but the sentence is garbled. &quot;will be logge=
d&quot;?<br>
<br>
&nbsp;&nbsp; The events below are identified at the time of this writing bu=
t the<br>
&nbsp;&nbsp; events are expandable.&nbsp; Depending on the implementation a=
nd<br>
&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^<br>
SD: this is a nit, but &quot;set of events is extensible&quot;, I think.</f=
ont></div>
</div>
</span>
<div><br>
</div>
<div>[Senthil] Agree. (to both comments).</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp; configuration various IE's specified can be included or ignore=
d.<br>
<br>
5.6.1.&nbsp; NAT44 create and delete session events<br>
<br>
&nbsp;&nbsp; These events will be generated when a NAT44 session is created=
 or<br>
&nbsp;&nbsp; deleted.&nbsp; The template will be the same, the natEvent wil=
l indicate<br>
&nbsp;&nbsp; whether it is a create or a delete event.&nbsp; The following =
is a<br>
&nbsp;&nbsp; template of the event.<br>
<br>
&nbsp;&nbsp; The destination address and port information is optional as re=
quired<br>
&nbsp;&nbsp; by [RFC6888].&nbsp; However, when the destination information =
is<br>
&nbsp;&nbsp; suppressed, the session log event contains the same informatio=
n as<br>
&nbsp;&nbsp; the BIB event.&nbsp; In such cases, the NAT device SHOULD NOT =
send both<br>
&nbsp;&nbsp; BIB and session events.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbs=
p;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; vlanID=
/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
sourceIPv4Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&n=
bsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv4A=
ddress&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&n=
bsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; source=
TransportPort&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;=
&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNAPTsourceTransportPort&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 =
|&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationI=
Pv4Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<b=
r>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; postNATDestinationIPv4Address&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nb=
sp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; destinationTranspo=
rtPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTdestinationTransportPort |&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp;=
 No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; intern=
alAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; extern=
alAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; Table 5: NAT44 Session delete/create template<br>
<br>
5.6.2.&nbsp; NAT64 create and delete session events<br>
<br>
&nbsp;&nbsp; These events will be generated when a NAT64 session is created=
 or<br>
&nbsp;&nbsp; deleted.&nbsp; The following is a template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbs=
p;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; vlanID=
/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
sourceIPv6Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv4A=
ddress&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&n=
bsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; source=
TransportPort&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;=
&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNAPTsourceTransportPort&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 =
|&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationI=
Pv6Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; postNATDestinationIPv4Address&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nb=
sp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; destinationTranspo=
rtPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTdestinationTransportPort |&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp;=
 No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; intern=
alAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; extern=
alAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 6:=
 NAT64 session create/delete event template<br>
<br>
5.6.3.&nbsp; NAT44 BIB create and delete events<br>
<br>
&nbsp;&nbsp; These events will be generated when a NAT44 Bind entry is crea=
ted or<br>
&nbsp;&nbsp; deleted.&nbsp; The following is a template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbs=
p;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
vlanID/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; sourceIPv4Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&n=
bsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNATSourc=
eIPv4Address&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nb=
sp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
sourceTransportPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTsourceTransportP=
ort |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp=
;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
internalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
externalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Table 7: NAT44 BIB create/delete event template<br>
<br>
5.6.4.&nbsp; NAT64 BIB create and delete events<br>
<br>
&nbsp;&nbsp; These events will be generated when a NAT64 Bind entry is crea=
ted or<br>
&nbsp;&nbsp; deleted.&nbsp; The following is a template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbs=
p;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
vlanID/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; sourceIPv6Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNATSourc=
eIPv4Address&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nb=
sp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
sourceTransportPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTsourceTransportP=
ort |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp=
;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
internalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
externalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Table 8: NAT64 BIB create/delete event template<br>
<br>
5.6.5.&nbsp; Addresses Exhausted event<br>
<br>
&nbsp;&nbsp; This event will be generated when a NAT device runs out of glo=
bal<br>
&nbsp;&nbsp; IPv4 addresses in a given pool of addresses.&nbsp; Typically, =
this event<br>
&nbsp;&nbsp; would mean that the NAT device wont be able to create any new<=
br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^<br>
SD: &quot;won't&quot;</font></div>
</div>
</span>
<div><br>
</div>
<div>[Senthil] Ok.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp; translations until some addresses/ports are freed.&nbsp; This =
event SHOULD<br>
&nbsp;&nbsp; be rate limited as many packets hitting the device at the same=
 time<br>
&nbsp;&nbsp; will trigger a burst of addresses exhausted events.<br>
<br>
&nbsp;&nbsp; The following is a template of the event.&nbsp; Note that eith=
er the NAT<br>
&nbsp;&nbsp; pool name or the nat pool identifier should be logged, but not=
 both.<br>
<br>
SD: I lack understanding, but I didn't see anything that looked like a NAT =
pool name in the template. Did I miss something?</font></div>
</div>
</span>
<div><br>
</div>
<div>[Senthil] We decided not to use a string like a pool name instead use =
a poolID, which is a unique identifier for each pool name. The reason being=
 that the logs could become fairly large&nbsp;</div>
<div>If we have to carry the names and some of the NAT engines implement th=
is in the hardware that lacks the string processing capability.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; &#43;---------------&#43;-------------&#43;-----------&#43;=
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp; Field Name&nbsp; | Size (bits) | Mandatory |<=
br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; &#43;---------------&#43;-------------&#43;-----------&#43;=
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp; timeStamp&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbs=
p; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; | natInstanceID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;=
&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp; natPoolID&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbs=
p; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; &#43;---------------&#43;-------------&#43;-----------&#43;=
<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; Table 9: Address Exhausted event template<br>
<br>
5.6.6.&nbsp; Ports Exhausted event<br>
<br>
&nbsp;&nbsp; This event will be generated when a NAT device runs out of por=
ts for<br>
&nbsp;&nbsp; a global IPv4 address.&nbsp; Port exhaustion shall be reported=
 per<br>
&nbsp;&nbsp; protocol (UDP, TCP etc).&nbsp; This event SHOULD be rate limit=
ed as many<br>
&nbsp;&nbsp; packets hitting the device at the same time will trigger a bur=
st of<br>
&nbsp;&nbsp; port exhausted events.<br>
<br>
&nbsp;&nbsp; The following is a template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-----------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
; | Size (bits) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-----------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&n=
bsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&=
nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8=
 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNATSourceIPv4A=
ddress |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&n=
bsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; =
protocolIdentifier&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-----------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; Table 10: Ports Exhausted event template<br>
<br>
5.6.7.&nbsp; Quota exceeded events<br>
<br>
&nbsp;&nbsp; This event will be generated when a NAT device cannot allocate=
<br>
&nbsp;&nbsp; resources as a result of an administratively defined policy.&n=
bsp; The<br>
&nbsp;&nbsp; quota exceeded event templates are described below<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; ^<br>
SD: missing period</font></div>
</div>
</span>
<div>[Senthil] Ok.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier New,Courier=
,monospace"><br>
<br>
5.6.7.1.&nbsp; Maximum session entries exceeded<br>
<br>
&nbsp;&nbsp; The maximum session entries exceeded is generated when the<br>
&nbsp;&nbsp; administratively configured limit is reached.&nbsp; The follow=
ing is the<br>
&nbsp;&nbsp; template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp; | Size (bits) | Mandat=
ory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbs=
p;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natInstanceID&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes=
&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natLimitEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; | configuredLimit |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ta=
ble 11: Session Entries Exceeded event template<br>
<br>
5.6.7.2.&nbsp; Maximum BIB entries exceeded<br>
<br>
&nbsp;&nbsp; The maximum BIB entries exceeded is generated when the<br>
&nbsp;&nbsp; administratively configured limit is reached.&nbsp; The follow=
ing is the<br>
&nbsp;&nbsp; template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp; | Size (bits) | Mandat=
ory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbs=
p;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natInstanceID&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes=
&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natLimitEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; | configuredLimit |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; Table 12: BIB Entries Exceeded event template<br>
<br>
5.6.7.3.&nbsp; Maximum entries per user exceeded<br>
<br>
&nbsp;&nbsp; This event is generated when a single user reaches the<br>
&nbsp;&nbsp; administratively configured limit.&nbsp; The following is the =
template of<br>
&nbsp;&nbsp; the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) |&nbsp;&=
nbsp; Mandatory&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp; natInstanceID&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp; natLimitEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; =
configuredLimit&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | vlanID/ingre=
ssVRFID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; source=
IPv4 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 | Y=
es for NAT44 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; source=
IPv6 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 | Yes fo=
r NAT64 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 13=
: Per-user Entries Exceeded event template<br>
<br>
5.6.7.4.&nbsp; Maximum active host or subscribers exceeded<br>
<br>
&nbsp;&nbsp; This event is generated when the number of allowed hosts or<br=
>
&nbsp;&nbsp; subscribers reaches the administratively configured limit.&nbs=
p; The<br>
&nbsp;&nbsp; following is the template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp; | Size (bits) | Mandat=
ory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbs=
p;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natInstanceID&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes=
&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natLimitEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; | configuredLimit |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 14: Maximum hosts/subscrib=
ers Exceeded event template<br>
<br>
5.6.7.5.&nbsp; Maximum fragments pending reassembly exceeded<br>
<br>
&nbsp;&nbsp; This event is generated when the number of fragments pending<b=
r>
&nbsp;&nbsp; reassembly reaches the administratively configured limit.&nbsp=
; The<br>
&nbsp;&nbsp; following is the template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) |&nbsp;&=
nbsp; Mandatory&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; =
natInstanceID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; =
natLimitEvent&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; config=
uredLimit&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | internalAddressRea=
lm |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | vlanID/ingressVRFI=
D&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; sourceIPv4 a=
ddress&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 | Y=
es for NAT44 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; sourceIPv6 a=
ddress&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 | Yes fo=
r NAT64 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-------&#43;-------------&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 15: Maximum fragments pending re=
assembly Exceeded event<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; template<br>
<br>
5.6.8.&nbsp; Threshold reached events<br>
<br>
&nbsp;&nbsp; This event will be generated when a NAT device reaches a opera=
tor<br>
&nbsp;&nbsp; configured threshold when allocating resources.&nbsp; The thre=
shold<br>
&nbsp;&nbsp; reached events are described in the section above.&nbsp; The f=
ollowing is<br>
&nbsp;&nbsp; a template of the individual events.<br>
<br>
5.6.8.1.&nbsp; Address pool high or low threshold reached<br>
<br>
&nbsp;&nbsp; This event is generated when the high or low threshold is reac=
hed for<br>
&nbsp;&nbsp; the address pool.&nbsp; The template is the same for both high=
 and low<br>
&nbsp;&nbsp; threshold events<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp; | Size (bits) | =
Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbs=
p;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp; natInstanceID&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbs=
p; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; | natThresholdEvent |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp; natPoolID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbs=
p;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp; configuredLimit&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp; Table 16: Address pool high/low threshold reached =
event template<br>
<br>
5.6.8.2.&nbsp; Address and port high threshold reached<br>
<br>
&nbsp;&nbsp; This event is generated when the high threshold is reached for=
 the<br>
&nbsp;&nbsp; address pool and ports.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp; | Size (bits) | =
Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbs=
p;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp; natInstanceID&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbs=
p; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; | natThresholdEvent |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp; configuredLimit&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 17: Address port high threshold =
reached event template<br>
<br>
5.6.8.3.&nbsp; Per-user Address and port high threshold reached<br>
<br>
&nbsp;&nbsp; This event is generated when the high threshold is reached for=
 the<br>
&nbsp;&nbsp; per-user address pool and ports.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) |&nbsp;&=
nbsp; Mandatory&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp; natInstanceID&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; natThr=
esholdEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3=
2 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; =
configuredLimit&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | vlanID/ingre=
ssVRFID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; source=
IPv4 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 | Y=
es for NAT44 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; source=
IPv6 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 | Yes fo=
r NAT64 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp; Table 18: Per-user Address port high threshold reached event t=
emplate<br>
<br>
5.6.8.4.&nbsp; Global Address mapping high threshold reached<br>
<br>
&nbsp;&nbsp; This event is generated when the high is reached for the per-u=
ser<br>
&nbsp;&nbsp; address pool and ports.&nbsp; This is generated only by NAT de=
vices that<br>
&nbsp;&nbsp; use a address pooling behavior of paired.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#=
43;---------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp; | Size (bi=
ts) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#=
43;---------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&=
nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
|&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbs=
p;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp; natThresholdEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp; configuredLimit&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | =
vlanID/ingressVRFID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#=
43;---------------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 19: Global Address mapping high =
threshold reached event<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; template<br>
<br>
5.6.9.&nbsp; Address binding create and delete events<br>
<br>
&nbsp;&nbsp; These events will be generated when a NAT device binds a local=
<br>
&nbsp;&nbsp; address with a global address and when the global address is f=
reed.<br>
&nbsp;&nbsp; This binding event happens when the first packet of the first =
flow<br>
&nbsp;&nbsp; from a host in the private realm.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp; | Size (bits) |&nbsp;&nbsp; Mandatory&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<=
br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv4 a=
ddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; 32 | Yes for NAT44 |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv6 a=
ddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; 128 | Yes for NAT64 |<br>
&nbsp;&nbsp;&nbsp;&nbsp; | Translated Source IPv4 Address |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp; Table 20: NAT Address Binding template<br>
<br>
5.6.10.&nbsp; Port block allocation and de-allocation<br>
<br>
&nbsp;&nbsp; This event will be generated when a NAT device allocates/de-al=
locates<br>
&nbsp;&nbsp; ports in a bulk fashion, as opposed to allocating a port on a =
per<br>
&nbsp;&nbsp; flow basis.<br>
<br>
&nbsp;&nbsp; portRangeStart represents the starting value of the range.<br>
<br>
&nbsp;&nbsp; portRangeEnd represents the ending value of the range.<br>
<br>
&nbsp;&nbsp; NAT devices would do this in order to reduce logs and potentia=
lly to<br>
&nbsp;&nbsp; limit the number of connections a subscriber is allowed to use=
.&nbsp; In<br>
&nbsp;&nbsp; the following Port Block allocation template, the portRangeSta=
rt and<br>
&nbsp;&nbsp; portRangeEnd must be specified.<br>
<br>
<br>
Sivakumar &amp; Penno&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Expires Aug=
ust 15, 2014&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; [Page 17]<br>
<br>
Internet-Draft&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IPFIX =
IEs for NAT logging&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; F=
ebruary 2014<br>
<br>
&nbsp;&nbsp; It is up to the implementation to choose to consolidate log re=
cords<br>
&nbsp;&nbsp; in case two consecutive port ranges for the same user are allo=
cated<br>
&nbsp;&nbsp; or freed.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp; | Size (bits) |&nbsp;&nbsp; Mandatory&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<=
br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv4 a=
ddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; 32 | Yes for NAT44 |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv6 a=
ddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; 128 | Yes for NAT64 |<br>
&nbsp;&nbsp;&nbsp;&nbsp; | Translated Source IPv4 Address |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
portRangeStart&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; portRangeEnd&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 21=
: NAT Port Block Allocation event template<br>
<br>
6.&nbsp; Encoding<br>
<br>
6.1.&nbsp; IPFIX<br>
<br>
&nbsp;&nbsp; This document uses IPFIX as the encoding mechanism to describe=
 the<br>
&nbsp;&nbsp; logging of NAT events.&nbsp; However, the information that sho=
uld be<br>
&nbsp;&nbsp; logged SHOULD be the same irrespective of what kind of encodin=
g<br>
&nbsp;&nbsp; scheme is used.&nbsp; IPFIX is chosen because is it an IETF st=
andard that<br>
&nbsp;&nbsp; meets all the needs for a reliable logging mechanism.&nbsp; IP=
FIX provides<br>
&nbsp;&nbsp; the flexibility to the logging device to define the data sets =
that it<br>
&nbsp;&nbsp; is logging.&nbsp; The IEs specified for logging MUST be the sa=
me<br>
&nbsp;&nbsp; irrespective of the encoding mechanism used.<br>
<br>
7.&nbsp; Acknowledgements<br>
<br>
&nbsp;&nbsp; Thanks to Dan Wing, Selvi Shanmugam, Mohamed Boucadir, Jacni Q=
in<br>
&nbsp;&nbsp; Ramji Vaithianathan, Simon Perreault, Jean-Francois Tremblay, =
Paul<br>
&nbsp;&nbsp; Aitken and Julia Renouard for their review and comments.<br>
<br>
8.&nbsp; IANA Considerations<br>
<br>
&nbsp;&nbsp; The following information elements are requested from IANA IPF=
IX<br>
&nbsp;&nbsp; registry.<br>
<br>
&nbsp;&nbsp; natInstanceId<br>
<br>
&nbsp;&nbsp; externalAddressRealm<br>
<br>
&nbsp;&nbsp; natLimitEvent<br>
<br>
9.&nbsp; Management Considerations<br>
<br>
&nbsp;&nbsp; This section considers requirements for management of the log =
system<br>
&nbsp;&nbsp; to support logging of the events described above.&nbsp; It fir=
st covers<br>
&nbsp;&nbsp; requirements applicable to log management in general.&nbsp; An=
y additional<br>
&nbsp;&nbsp; standardization required to fullfil these requirements is out =
of<br>
&nbsp;&nbsp; scope of the present document.&nbsp; Some management considera=
tions is<br>
&nbsp;&nbsp; covered in [I-D.behave-syslog-nat-logging].&nbsp; This documen=
t covers the<br>
&nbsp;&nbsp; additional considerations.<br>
<br>
9.1.&nbsp; Ability to collect events from multiple NAT devices<br>
<br>
&nbsp;&nbsp; An IPFIX collector should be able to collect events from multi=
ple NAT<br>
&nbsp;&nbsp; devices and be able to decipher events based on the sourceID i=
n the<br>
&nbsp;&nbsp; IPFIX header.<br>
<br>
9.2.&nbsp; Ability to suppress events<br>
<br>
&nbsp;&nbsp; The exhaustion events can be overwhelming during traffic burst=
s and<br>
&nbsp;&nbsp; hence should be handled by the NAT devices to rate limit them =
before<br>
&nbsp;&nbsp; sending them to the collectors.&nbsp; For eg. when the port ex=
haustion<br>
&nbsp;&nbsp; happens during bursty conditions, instead of sending a port<br=
>
&nbsp;&nbsp; exhaustion event for every packet, the exhaustion events shoul=
d be<br>
&nbsp;&nbsp; rate limited by the NAT device.<br>
<br>
10.&nbsp; Security Considerations<br>
<br>
&nbsp;&nbsp; None.<br>
<br>
11.&nbsp; References<br>
<br>
11.1.&nbsp; Normative References<br>
<br>
&nbsp;&nbsp; [RFC2119]&nbsp; Bradner, S., &quot;Key words for use in RFCs t=
o Indicate<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Requirement Levels&quot;, BCP 14, RFC 2119, March 1997.<br>
<br>
&nbsp;&nbsp; [RFC2663]&nbsp; Srisuresh, P. and M. Holdrege, &quot;IP Networ=
k Address<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Translator (NAT) Terminology and Considerations&quot;, RFC<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; 2663, August 1999.<br>
<br>
&nbsp;&nbsp; [RFC4787]&nbsp; Audet, F. and C. Jennings, &quot;Network Addre=
ss Translation<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; (NAT) Behavioral Requirements for Unicast UDP&quot;, BCP 127,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; RFC 4787, January 2007.<br>
<br>
&nbsp;&nbsp; [RFC5382]&nbsp; Guha, S., Biswas, K., Ford, B., Sivakumar, S.,=
 and P.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Srisuresh, &quot;NAT Behavioral Requirements for TCP&quot;, BCP 142,<br=
>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; RFC 5382, October 2008.<br>
<br>
&nbsp;&nbsp; [RFC6146]&nbsp; Bagnulo, M., Matthews, P., and I. van Beijnum,=
 &quot;Stateful<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; NAT64: Network Address and Protocol Translation from IPv6<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Clients to IPv4 Servers&quot;, RFC 6146, April 2011.<br>
<br>
&nbsp;&nbsp; [RFC6302]&nbsp; Durand, A., Gashinsky, I., Lee, D., and S. She=
ppard,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &quot;Logging Recommendations for Internet-Facing Servers&quot;, BCP<br=
>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; 162, RFC 6302, June 2011.<br>
<br>
&nbsp;&nbsp; [RFC6888]&nbsp; Perreault, S., Yamagata, I., Miyakawa, S., Nak=
agawa, A.,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; and H. Ashida, &quot;Common Requirements for Carrier-Grade NATs<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; (CGNs)&quot;, BCP 127, RFC 6888, April 2013.<br>
<br>
11.2.&nbsp; Informative References<br>
<br>
&nbsp;&nbsp; [I-D.ietf-behave-syslog-nat-logging]<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Chen, Z., Zhou, C., Tsou, T., and T. Taylor, &quot;Syslog<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Format for NAT Logging&quot;, draft-ietf-behave-syslog-nat-<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; logging-06 (work in progress), January 2014.<br>
<br>
&nbsp;&nbsp; [IPFIX-IANA]<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; IANA, &quot;IPFIX Information Elements registry&quot;,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; <a class=3D"moz-txt-link-rfc2396E" href=3D"http://www.iana.org/assignme=
nts/ipfix">
&lt;http://www.iana.org/assignments/ipfix&gt;</a>.<br>
<br>
&nbsp;&nbsp; [RFC5101bis]<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Claise, B. and B. Trammel, &quot;Specification of the IP Flow<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Information eXport (IPFIX) Protocol for the Exchange of<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Flow Information&quot;, July 2013.<br>
<br>
&nbsp;&nbsp; [RFC5102bis]<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Claise, B. and B. Trammel, &quot;Information Model for IP Flow<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Information eXport (IPFIX)&quot;, February 2013.<br>
<br>
&nbsp;&nbsp; [RFC5470]&nbsp; Sadasivan, G., Brownlee, N., Claise, B., and J=
. Quittek,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &quot;Architecture for IP Flow Information Export&quot;, RFC 5470,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; March 2009.<br>
<br>
Authors' Addresses<br>
<br>
&nbsp;&nbsp; Senthil Sivakumar<br>
&nbsp;&nbsp; Cisco Systems<br>
&nbsp;&nbsp; 7100-8 Kit Creek Road<br>
&nbsp;&nbsp; Research Triangle Park, North Carolina&nbsp; 27709<br>
&nbsp;&nbsp; USA<br>
<br>
&nbsp;&nbsp; Phone: &#43;1 919 392 5158<br>
<br>
&nbsp;&nbsp; Renaldo Penno<br>
&nbsp;&nbsp; Cisco Systems<br>
&nbsp;&nbsp; 170 W Tasman Drive<br>
&nbsp;&nbsp; San Jose, California&nbsp; 95035<br>
&nbsp;&nbsp; USA<br>
<br>
&nbsp;&nbsp; Email: <a class=3D"moz-txt-link-abbreviated" href=3D"mailto:re=
penno@cisco.com">repenno@cisco.com</a><br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
Sivakumar &amp; Penno&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Expires Aug=
ust 15, 2014&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; [Page 21]</font></div>
</div>
</span>
</body>
</html>

--_000_CF89605B1009FBssenthilciscocom_--


From nobody Wed May  7 08:46:16 2014
Return-Path: <ietf-ipr@ietf.org>
X-Original-To: behave@ietfa.amsl.com
Delivered-To: behave@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 72A431A03C7; Wed,  7 May 2014 08:46:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NTIISDTrMPCj; Wed,  7 May 2014 08:46:12 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 574341A0388; Wed,  7 May 2014 08:46:12 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: IETF Secretariat <ietf-ipr@ietf.org>
To: philip_matthews@magma.ca,iljitsch@muada.com,marcelo@it.uc3m.es
X-Test-IDTracker: no
X-IETF-IDTracker: 5.4.2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20140507154612.27685.72540.idtracker@ietfa.amsl.com>
Date: Wed, 07 May 2014 08:46:12 -0700
Archived-At: http://mailarchive.ietf.org/arch/msg/behave/8MUWo_BPHFSyxh5qLW5tGuUlKVw
Cc: behave@ietf.org, dthaler@microsoft.com, mls.ietf@gmail.com, spencerdawkins.ietf@gmail.com, dwing@cisco.com, ipr-announce@ietf.org
Subject: [BEHAVE] IPR Disclosure: Hitachi, Ltd.'s Statement about IPR related to RFC 6146
X-BeenThere: behave@ietf.org
X-Mailman-Version: 2.1.15
List-Id: mailing list of BEHAVE IETF WG <behave.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/behave>, <mailto:behave-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/behave/>
List-Post: <mailto:behave@ietf.org>
List-Help: <mailto:behave-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 May 2014 15:46:13 -0000

Dear Philip Matthews, Iljitsch van Beijnum, Marcelo Bagnulo:

 An IPR disclosure that pertains to your RFC entitled "Stateful NAT64: Network
Address and Protocol Translation from IPv6 Clients to IPv4 Servers" (RFC6146)
was submitted to the IETF Secretariat on 2014-05-06 and has been posted on the
"IETF Page of Intellectual Property Rights Disclosures"
(https://datatracker.ietf.org/ipr/2355/). The title of the IPR disclosure is
"Hitachi, Ltd.'s Statement about IPR related to RFC 6146."");

The IETF Secretariat


From nobody Wed May  7 08:47:00 2014
Return-Path: <ietf-ipr@ietf.org>
X-Original-To: behave@ietfa.amsl.com
Delivered-To: behave@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7463A1A07A0; Wed,  7 May 2014 08:46:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GJWgWgMwzcSn; Wed,  7 May 2014 08:46:57 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 627E61A0397; Wed,  7 May 2014 08:46:57 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: IETF Secretariat <ietf-ipr@ietf.org>
To: philip_matthews@magma.ca, ajs@shinkuro.com, iljitsch@muada.com, marcelo@it.uc3m.es
X-Test-IDTracker: no
X-IETF-IDTracker: 5.4.2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20140507154657.7041.30514.idtracker@ietfa.amsl.com>
Date: Wed, 07 May 2014 08:46:57 -0700
Archived-At: http://mailarchive.ietf.org/arch/msg/behave/Pm3CFr-_5o04oQ4wRg2DxsyCqEc
Cc: behave@ietf.org, dthaler@microsoft.com, mls.ietf@gmail.com, spencerdawkins.ietf@gmail.com, dwing@cisco.com, ipr-announce@ietf.org
Subject: [BEHAVE] IPR Disclosure: Hitachi, Ltd.'s Statement about IPR related to RFC 6147
X-BeenThere: behave@ietf.org
X-Mailman-Version: 2.1.15
List-Id: mailing list of BEHAVE IETF WG <behave.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/behave>, <mailto:behave-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/behave/>
List-Post: <mailto:behave@ietf.org>
List-Help: <mailto:behave-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 May 2014 15:46:58 -0000

Dear Philip Matthews, Andrew Sullivan, Iljitsch van Beijnum, Marcelo Bagnulo:

 An IPR disclosure that pertains to your RFC entitled "DNS64: DNS Extensions for
Network Address Translation from IPv6 Clients to IPv4 Servers" (RFC6147) was
submitted to the IETF Secretariat on 2014-05-06 and has been posted on the "IETF
Page of Intellectual Property Rights Disclosures"
(https://datatracker.ietf.org/ipr/2356/). The title of the IPR disclosure is
"Hitachi, Ltd.'s Statement about IPR related to RFC 6147."");

The IETF Secretariat


From nobody Sat May 24 19:20:31 2014
Return-Path: <spencerdawkins.ietf@gmail.com>
X-Original-To: behave@ietfa.amsl.com
Delivered-To: behave@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9BD3F1A0088 for <behave@ietfa.amsl.com>; Fri, 23 May 2014 14:06:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.682
X-Spam-Level: *
X-Spam-Status: No, score=1.682 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_FONT_FACE_BAD=0.981, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LNXvzMhRh-jW for <behave@ietfa.amsl.com>; Fri, 23 May 2014 14:06:03 -0700 (PDT)
Received: from mail-oa0-x236.google.com (mail-oa0-x236.google.com [IPv6:2607:f8b0:4003:c02::236]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AE6D61A0086 for <behave@ietf.org>; Fri, 23 May 2014 14:06:02 -0700 (PDT)
Received: by mail-oa0-f54.google.com with SMTP id j17so6201969oag.41 for <behave@ietf.org>; Fri, 23 May 2014 14:06:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type; bh=bTEw0YY5Gus7PTk9q9edjp3WZEFb3wO0D+NzGfFLtSM=; b=LRS9FXsv6KwZhpMb2Yojg0v/WaSLFOKACuTcddKtr1GGokjxFjIF8PDYIco/utDSol v64E6ELa9/rhTrldN+dcMpIlee45DYxJmMMMs+ZqLmwS4QzNu7pWme9XeRgrt0zJvWbD kYW4j1Z19rO851rdTGlwEPtjz96UwlK/lw5cMcSzy85VGz9izS9dKvjVg07VntQxetSM prfFNTV3KybNdDV29a3g7OlL0gGWduCwedZg2f0AKGYef5iFF2RcWihPDY3UuQ1uw7J0 DP6mxixA/vB2dUsBziixIptckiDUcZbykdfmQt56xwVVXBgp9uUeVeJcB+YyZwwtalBG dsew==
X-Received: by 10.182.43.132 with SMTP id w4mr7921808obl.41.1400879160629; Fri, 23 May 2014 14:06:00 -0700 (PDT)
Received: from [192.168.0.13] (cpe-76-187-7-89.tx.res.rr.com. [76.187.7.89]) by mx.google.com with ESMTPSA id gp4sm7427596obb.17.2014.05.23.14.05.57 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Fri, 23 May 2014 14:05:59 -0700 (PDT)
Message-ID: <537FB834.3010705@gmail.com>
Date: Fri, 23 May 2014 16:05:56 -0500
From: Spencer Dawkins <spencerdawkins.ietf@gmail.com>
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: "Senthil Sivakumar (ssenthil)" <ssenthil@cisco.com>,  "draft-ietf-behave-ipfix-nat-logging@tools.ietf.org" <draft-ietf-behave-ipfix-nat-logging@tools.ietf.org>
References: <5362ADCB.4050802@gmail.com> <CF89605B.1009FB%ssenthil@cisco.com>
In-Reply-To: <CF89605B.1009FB%ssenthil@cisco.com>
Content-Type: multipart/alternative; boundary="------------030908080302000709080908"
Archived-At: http://mailarchive.ietf.org/arch/msg/behave/ocDkbdUjCjUZstUgCUv2o2hnh0Q
X-Mailman-Approved-At: Sat, 24 May 2014 19:20:28 -0700
Cc: "behave@ietf.org" <behave@ietf.org>
Subject: Re: [BEHAVE] AD Evaluation of draft-ietf-behave-ipfix-nat-logging-03
X-BeenThere: behave@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: mailing list of BEHAVE IETF WG <behave.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/behave>, <mailto:behave-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/behave/>
List-Post: <mailto:behave@ietf.org>
List-Help: <mailto:behave-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 May 2014 21:06:10 -0000

This is a multi-part message in MIME format.
--------------030908080302000709080908
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 8bit


On 05/02/2014 02:20 PM, Senthil Sivakumar (ssenthil) wrote:
> Hi Spencer,
> Thanks for the thorough review.
> Please see inline for [Senthil]. If you agree, I will submit another 
> version fixing all the issues raised and agreed upon. I will wait for 
> your response.

Hi, Senthil,

Thanks for being responsive!

Just as a high-order bit, many of the questions I asked are whether the 
draft uses "required" to mean "this is the way it works" - there's a 
difference between "the sender transmits a log" and "the sender is 
required to transmit a log". Does that make sense?

Ths draft says it uses requirements language as per RFC 2119, and RFC 
2119 says

6. Guidance in the use of these Imperatives

    Imperatives of the type defined in this memo must be used with care
    and sparingly.  In particular, they MUST only be used where it is
    actually required for interoperation or to limit behavior which has
    potential for causing harm (e.g., limiting retransmisssions)  For
    example, they must not be used to try to impose a particular method
    on implementors where the method is not required for
    interoperability.

It's also worth mentioning that RFC 2119 is silent on case for 
requirements language, your requirements terminology section only shows 
upper case examples, and most of the cases I'm asking about are in lower 
case, which makes it less clear whether you intend "require" to be an 
RFC 2119 requirement word or not. This is a continuing source of 
controversy in the IETF, especially during cross-area review - my 
suggestion is that you either change the requirements language statement 
to include a statement about whether lower-case versions are intended as 
requirements language, or don't use the lower-case terms in the document.

I'll try to be clear in my detailed comments, but that's often what I'm 
trying to get at.

> Thanks
> Senthil
>
> From: Spencer Dawkins <spencerdawkins.ietf@gmail.com 
> <mailto:spencerdawkins.ietf@gmail.com>>
> Date: Thursday, May 1, 2014 4:25 PM
> To: "draft-ietf-behave-ipfix-nat-logging@tools.ietf.org 
> <mailto:draft-ietf-behave-ipfix-nat-logging@tools.ietf.org>" 
> <draft-ietf-behave-ipfix-nat-logging@tools.ietf.org 
> <mailto:draft-ietf-behave-ipfix-nat-logging@tools.ietf.org>>
> Cc: "behave@ietf.org <mailto:behave@ietf.org>" <behave@ietf.org 
> <mailto:behave@ietf.org>>
> Subject: AD Evaluation of draft-ietf-behave-ipfix-nat-logging-03
> Resent-From: <draft-alias-bounces@tools.ietf.org 
> <mailto:draft-alias-bounces@tools.ietf.org>>
> Resent-To: <repenno@cisco.com <mailto:repenno@cisco.com>>, Senthil 
> Sivakumar <ssenthil@cisco.com <mailto:ssenthil@cisco.com>>
> Resent-Date: Thursday, May 1, 2014 4:26 PM
>
> Dear draft-ietf-behave-ipfix-nat-logging Authors,
>
> I've completed my AD evaluation for this draft. I found some things 
> I'd like to see changed before proceeding, but most are editorial. 
> Please take a look, and let me know what you think.
>
> My notes follow ... you should be able to find my questions and 
> comments by searching for "SD:".
>
> Thanks,
>
> Spencer
>
> In the Abstract
>
>    NAT devices are required to log events like creation and deletion of
>                    ^^^^^^^^
> SD: Is this required, like, legally required, or ? Is it more like 
> "Operators need NAT devices to log events ..."?
> [Senthil] : It is the later, the network operators require the NAT 
> devices to be able to log events.

We don't usually include requirements language in the Abstract (that 
happens later, which is fine in the document body).

The longer I look at this, the more I think it's something like 
"Operators expect NAT devices to log events".

>
>    translations and information about the resources it is managing.  The
>    logs are required in many cases to identify an attacker or a host
>    that was used to launch malicious attacks and/or for various other
>    purposes of accounting.  Since there is no standard way of logging
>    this information, different NAT devices behave differently and hence
> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
> SD: Is this "different NAT devices log this information differently"?
> [Senthil] Correct, as the sentence says, "Since there is no standard 
> way…", each NAT device logs information in its own proprietary format.

I'm just trying to make sure the reader understands what you mean by 
"behave differently" - NAT devices also behave differently when 
NATting.  I had to guess at the meaning. Maybe everyone else will 
understand?

>    it is difficult to expect a consistent behavior.  The lack of a
>    consistent way makes it difficult to write the collector applications
>    that would receive this data and process it to present useful
>    information.  This document describes the information that is
>    required to be logged by the NAT devices.
>    ^^^^^^^^^^^^^^^^^^^^^^^^
> SD: Same as previous question - is this "logged by"?
>
> [Senthil] If a NAT device is logging events, these are the 
> requirements that a NAT device should adhere to.

I know this seems tedious, but I'm not able to map what you provided as 
explanation onto the text you're explaining. What I'm seeing in the text is

A NAT MUST log this information

and what I'm seeing in your explanation is

IF a NAT is is logging information, here's how the NAT SHOULD log 
information.

I'm guessing that what you're saying is really "this document describes 
the information that logging NAT devices produce".

This doesn't matter yet (you're still in the abstract, which shouldn't 
be providing requirements anyway), but in the body of the document, it 
needs to be clear.

> 2.  Introduction
>
>    The IPFIX Protocol [RFC5101bis] defines a generic push mechanism for
>    exporting information and events.  The IPFIX Information Model
>    [IPFIX-IANA] defines a set of standard Information Elements (IEs)
>    which can be carried by the IPFIX protocol.  This document details
>    the IPFIX Information Elements(IEs) that are required for logging by
>    a NAT device.  The document will specify the format of the IE's that
>    are required to be logged by the NAT device and all the optional
>        ^^^^^^^^^^^^^^^^^^^^^
> SD: Now that we're in the document body, if this is required, 
> shouldn't there be a reference to where the requirements are stated?
> [Senthil] This is the document that is specifying those requirements. 
> Do you have any other suggestions of wording instead of "required by", 
> would it be fine if I change the sentence from
> "required to be logged" to "SHOULD be logged"?

Sorry, my first set of comments was bogus. What triggered my comments 
was the use of lower-case terms from RFC 2119 (see my explanation above).

This could be "are REQUIRED" (the RFC 2119 requirements language you 
said you're using), or "are required" (if you change your paragraph 
about requirements language to say that case doesn't matter).

But "REQUIRED" is "MUST", so changing to "SHOULD" would be a change in 
your intended meaning.

>
>    This document and [I-D.behave-syslog-nat-logging] are provided in
>    order to standardize the events and parameters to be recorded, using
>    IPFIX [RFC5101bis] and SYSLOG [RFC5424]respectively.

I'm sorry I missed this question the first time. Is there a relationship 
with the MIB revision?

> 3.  Scope
>
>    This document provides the information model to be used for logging
>    the NAT devices including Carrier Grade NAT (CGN) events.  This
> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
> SD: This sentence seems somewhat turned around - "logging events", not 
> "logging the NAT devices".
> [Senthil] Agree, I will change this to "logging the NAT events".

Thanks.

>    document focuses exclusively on the specification of IPFIX IE's.
>    This document does not provide guidance on the transport protocol
>    like TCP, UDP or SCTP that is to be used to log NAT events.  The log
>    events SHOULD NOT be lost but the choice of the actual transport
>    protocol is beyond the scope of this document.
>
> SD: I'm not understanding why this last sentence is needed, especially 
> with a normative requirement for what you do when you are doing 
> something outside the scope of the document ...
> [Senthil] Are you objecting to the second part of the last sentence 
> "the choice of actual transport…", I think the requirement is that the 
> LOG events should not be lost is valid.

I'm sorry, my question wasn't clear. What I intended to say was that I 
was confused because the text said "not providing guidance on the choice 
of a transport protocol", but then provided a requirement about the 
implications of that choice (using a SHOULD).

So let me try to be clearer. I think what you're saying is

- you can use any transport protocol, but you SHOULDn't lose anything

I'm thinking this may be underspecified, although I don't know what 
IPFIX usually expects from transport protocols, so please be patient.

First, I'm confused by the SHOULD with no qualification. When is it OK 
to lose LOG events?

Second, you're not giving guidance on selecting a transport protocol, 
but you are giving guidance about expecting a reliable data channel, 
whether MUST be reliable or SHOULD be reliable. Are there other 
transport characteristics that you expect? For instance, is in-order 
delivery assumed? Is duplicate detection by IPFIX assumed (if a log 
arrives twice, does IPFIX notice)?

Third, are IPFIX implementations so transport protocol-agnostic that if 
my NAT device decides to to send logs using SCTP with partial 
reliability, I should expect that to work with any collector that 
implements this specification?

It happens that I co-chaired MEDIACTRL when the specification said "TCP 
or SCTP", and got feedback during AD evaluation that if we didn't pick a 
mandatory to implement transport protocol, that wouldn't guarantee 
interoperation between two standard-conforming devices.

>
>    The existing IANA IPFIX IEs registry [IPFIX-IANA] already has
>    assignments for many NAT logging events.  For convenience, this
>    document uses those same IEs.  However, as stated earlier, this
>    document is not defining IPFIX or NetFlow v9 as the framework for
>    logging.  Rather, the information contained in these elements is
>
> SD: I got lost on "these elements" - is that "the elements in the 
> existing registry"
> [Senthil] Yes. How about "Rather, the information elements as defined 
> in the IPFIX-IANA registry is within the scope of this document"?

I think that's "are within", but yes, that works. Thanks.

>    within the scope of this document.
>
>    This document assumes that the NAT device will use the existing IPFIX
>    framework to send the log events to the collector.  This would mean
>    that the NAT device will specify the template that it is going to use
>    for each of the events.  The templates can be of varying length and
>    there could be multiple templates that a NAT device could use to log
>    the events.
>
>    The implementation details of the collector application is beyond the
>    scope of this document.
>
>    The optimization of logging the NAT events are left to the
>                                               ^^^
>    implementation and are beyond the scope of this document.
>                       ^^^
> SD: It's a nit, but those "are"s should be "is"s.
> [Senthil] Ok.

Thanks.

> 4.  Applicability
>
>    NAT logging based on IPFIX uses binary encoding and hence is very
>    efficient.  IPFIX based logging is recommended for environments where
>    a high volume of logging is required, for example, where per-flow
>    logging is needed.  However, IPFIX based logging requires a collector
>    that processes the binary data and requires a network management
>    application that converts this binary data to a human readable
>    format.
>
> 5.  Event based logging
>
>    An event in a NAT device can be viewed as a happening as it relates
>                                                ^^^^^^^^^
> SD: Is this "a state transition"? I found "a happening" somewhat odd.
> [Senthil] Yes, I can rephrase this as "viewed as a state transition as 
> it relates to" or "viewed as an action as it relates to", if that is ok.

If "a state transition" is correct, I'd prefer that (if it's correct :-) ).

>    to the management of NAT resources.  The creation and deletion of NAT
>    sessions and bindings are examples of events as it results in the
>    resources (addresses and ports) being allocated or freed. The events
>    can happen either through the processing of data packets flowing
>    through the NAT device or through an external entity installing
>    policies on the NAT router or as a result of an asynchronous event
>    like a timer.  The list of events are provided in Section 4.1.  Each
>    of these events SHOULD be logged, unless they are administratively
>    prohibited.  A NAT device MAY log these events to multiple collectors
>    if redundancy is required.  The network administrator will specify
>    the collectors to which the log records are to be sent.
>
>    A collector may receive NAT events from multiple CGN devices and
>    should be able to distinguish between the devices.  Each CGN device
>    ^^^^^^
> SD: I'm not sure why this isn't a SHOULD, or even a MUST.
>
>    should have a unique source ID to identify themselves.  The source ID
>    ^^^^^^
> SD: Again, I'm not sure why this isn't a SHOULD, or even a MUST.
>
> [Senthil] Well, this is NOT a statement for a NAT device, instead it 
> is a collector that some application writer will
> develop.

Don't you think you can levy requirements about that on the collector? I 
don't understand.

But beyond that, what I THINK the text is saying, is that multiple CGN 
devices can ("may") send to a single collector, that none of the CDN 
devices have to have a unique source ID to identify themselves 
("should", but not "must"), and that the collector is still expected to 
be able to distinguish among logs coming from multiple CGNs ("should").

Am I misreading this?

If not, do you think that works?

>    is part of the IPFIX template and data exchange.
>
>    Prior to logging any events, the NAT device MUST send the template of
>    the record to the collector to advertise the format of the data
>    record that it is using to send the events.  The templates can be
>    exchanged as frequently as required given the reliability of the
>    connection.  There SHOULD be a configurable timer for controlling the
>    template refresh.  NAT device SHOULD combine as many events as
>    possible in a single packet to effectively utilize the network
>    bandwidth.
>
> 5.1.  Logging of destination information
>
>    Logging of destination information in a NAT event has been discussed
>    in [RFC6302] and [RFC6888].  Logging of destination information
>    increases the size of each record and increases the need for storage
>    considerably.  It increases the number of log events generated
>    because when the same user connects to a different destination, it
>    results in a log record per destination address.  Logging of
>    destination information also results in the loss of privacy and hence
>    should be done with caution.  However, this draft provides the
>    necessary fields to log the destination information in cases where
>    they are required to be logged.
>
> 5.2.  Information Elements
>
>    The templates could contain a subset of the Information Elements(IEs)
>    shown in Table 1 depending upon the event being logged. For example
>    a NAT44 session creation template record will contain,
>                                             ^^^^
> SD: Is this the only possible NAT44 template? If so, fine, but if not, 
> perhaps "could contain", or "typically contains"?
>
> [Senthil] Yes, this is all the information that a NAT44 need to export 
> as it is the least common denominator.

My question is whether any other IEs might be added in the future, I 
think. If not, "will" is OK, but "MUST" would be clearer.

>    {sourceIPv4Adress, postNATSourceIPv4Address, destinationIpv4Address,
>    postNATDestinationIPv4Address, sourceTransportPort,
>    postNAPTSourceTransportPort, destinationTransportPort,
>    postNAPTDestTransportPort, internalAddressRealm, natEvent, timeStamp}
>
>    An example of the actual event data record is shown below - in a
>    readable form
>
>    {192.168.16.1, 201.1.1.100, 207.85.231.104, 207.85.231.104, 14800,
>    1024, 80, 80, 0, 1, 09:20:10:789}
>
>    A single NAT device could be exporting multiple templates and the
>    collector should support receiving multiple templates from the same
>    source.observationTimeMilliseconds
>
>    The following is the table of all the IE's that a CGN device would
>    need to export the events.  The formats of the IE's and the IPFIX IDs
>    are listed below.
>
> SD: I noticed that some IEs below have a name that matches 
> http://www.iana.org/assignments/ipfix/ipfix.xhtml#ipfix-information-elements 
> for the same IPFIX ID number, but others do not ("timeStamp" here 
> doesn't match "observationTimeMilliseconds", but both are IPFIX ID 
> 323, aren't they?) Is there a reason to use names that don't match the 
> IANA registry?
>
> [Senthil] Good question, in case of timeStamp, I was looking for 
> something that already existed in the IPFIX registry rather than 
> asking for a new one. However, the terminology of 
> "observationTimeMilliseconds" is not the terminology that we use in 
> the NAT drafts/rfc's. So I am open to suggestions here. I can clarify 
> in the description that is called observationTimeMilliSeconds". The 
> other field is internalAddressRealm and externalAddresRealm, this is 
> the terminology that we used in NAT MIB, syslog and other documents. 
> However, when we defined the IPFIX IE, we didn’t stick to the same 
> terminology, so I don’t know if I can go and ask the IPFIX IANA to 
> change the name. Again I am open to suggestions, the dillema is 
> whether I should stick to the existing IPFIX IANA terminology or the 
> behave documents terminology.

I'm way out of my depth on this one (sorry!).

Fortunately, the next stop for an AD-sponsored IPFIX specification is 
the IPFIX review team. Could you just add a note pointing this question 
out, and asking if they have any suggestions?

> +----------------------------------+--------+-------+---------------+
>    |            Field Name            |   Size |  IANA | Description  |
>    |                                  | (bits) | IPFIX |               |
>    |                                  |        |    ID |               |
> +----------------------------------+--------+-------+---------------+
>    |            timeStamp             |     64 |   323 | System Time  |
>    |                                  |        | |    when the   |
>    |                                  |        | |     event     |
>    |                                  |        | |    occured.   |
>    |          natInstanceId           |     32 |   TBD | NAT Instance |
>    |                                  |        |       | Identifier  |
>    |              vlanID              |     16 |    58 | VLAN ID in  |
>    |                                  |        | |    case of    |
>    |                                  |        |       | overlapping  |
>    |                                  |        | |    networks   |
>    |           ingressVRFID           |     32 |   234 | VRF ID in   |
>    |                                  |        | |    case of    |
>    |                                  |        |       | overlapping  |
>    |                                  |        | |    networks   |
>    |        sourceIPv4Address         |     32 |     8 | Source IPv4  |
>    |                                  |        | |    Address    |
>    |     postNATSourceIPv4Address     |     32 |   225 | Translated  |
>    |                                  |        |       | Source IPv4  |
>    |                                  |        | |    Address    |
>    |        protocolIdentifier        |      8 |     4 | Transport   |
>    |                                  |        | |    protocol   |
>    |       sourceTransportPort        |     16 |     7 | Source Port  |
>    |   postNAPTsourceTransportPort    |     16 |   227 | Translated  |
>    |                                  |        |       | Source port  |
>    |      destinationIPv4Address      |     32 |    12 | Destination  |
>    |                                  |        |       | IPv4 Address |
>    |  postNATDestinationIPv4Address   |     32 |   226 | Translated  |
>    |                                  |        | |      IPv4     |
>    |                                  |        |       | destination  |
>    |                                  |        | |    address    |
>    |     destinationTransportPort     |     16 |    11 | Destination  |
>    |                                  |        | |      port     |
>    | postNAPTdestinationTransportPort |     16 |   228 | Translated  |
>    |                                  |        |       | Destination  |
>    |                                  |        | |      port     |
>    |        sourceIPv6Address         |     27 |   128 | Source IPv6  |
>    |                                  |        | |    address    |
>    |      destinationIPv6Address      |    128 |    28 | Destination  |
>    |                                  |        |       | IPv6 address |
>    |     postNATSourceIPv6Address     |    128 |   281 | Translated  |
>    |                                  |        |       | source IPv6  |
>    |                                  |        | |    addresss   |
>    |  postNATDestinationIPv6Address   |    128 |   282 | Translated  |
>    |                                  |        |       | Destination  |
>    |                                  |        |       | IPv6 address |
>    |       internalAddressRealm       |      8 |   229 |     Source    |
>    |                                  |        |       | Address Realm |
>    |       externalAddressRealm       |      8 |   TBD | Destination  |
>    |                                  |        |       | Address Realm |
>    |             natEvent             |      8 |   230 | Type of Event |
>    |          portRangeStart          |     16 |   361 | Allocated   |
>    |                                  |        |       | port block  |
>    |                                  |        | |     start     |
>    |           portRangeEnd           |     16 |   362 | Allocated   |
>    |                                  |        |       | Port block  |
>    |                                  |        | |      end      |
>    |            natPoolID             |     32 |   283 |    NAT pool   |
>    |                                  |        |       | Identifier  |
>    |          natLimitEvent           |     32 |   TBD | Limit event  |
>    |                                  |        |       | identifier  |
> +----------------------------------+--------+-------+---------------+
>
>                       Table 1: Template format Table
>
> 5.3.  Definition of NAT Events
>
>    The following are the list of NAT events and the proposed event
>    values.  The list can be expanded in the future as necessary.  The
>    data record will have the corresponding natEvent value to identify
>    the event that is being logged.
>
>                    +--------------------------+--------+
>                    |        Event Name        | Values |
>                    +--------------------------+--------+
>                    |   NAT44 Session create   |      1 |
>                    |   NAT44 Session delete   |      2 |
>                    | NAT Addresses exhausted  |      3 |
>                    |   NAT64 Session create   |      4 |
>                    |   NAT64 Session delete   |      5 |
>                    |     NAT44 BIB create     |      6 |
>                    |     NAT44 BIB delete     |      7 |
>                    |     NAT64 BIB create     |      8 |
>                    |     NAT64 BIB delete     |      9 |
>                    |   NAT ports exhausted    |     10 |
>                    |      Quota exceeded      |     11 |
>                    |  Address binding create  |     12 |
>                    |  Address binding delete  |     13 |
>                    |  Port block allocation   |     14 |
>                    | Port block de-allocation |     15 |
>                    |    Threshold reached     |     16 |
>                    +--------------------------+--------+
>
>                         Table 2: NAT Event ID table
>
> 5.4.  Quota exceeded Event types
>
>    The following table shows the sub event types for the Quota exceeded
>    or limits reached event.  The events that can be reported are the
>    Maximum session entries limit reached, Maximum BIB entries limit
>    reached, Maximum session/BIB entries per user limit reached and
>    maximum subscribers or hosts limit reached.
>
> +---------------------------------------+--------+
>             |       Quota Exceeded Event Name       | Values |
> +---------------------------------------+--------+
>             |        Maximum Session entries        | 1 |
>             |          Maximum BIB entries          | 2 |
>             |        Maximum entries per user       | 3 |
>             |  Maximum active hosts or subscribers  | 4 |
>             |  Maximum fragments pending reassembly | 5 |
> +---------------------------------------+--------+
>
>                     Table 3: Quota Exceeded event table
>
> 5.5.  Threshold reached Event types
>
>    The following table shows the sub event types for the threshold
>    reached event.  The administrator can configure the thresholds and
>    whenever the threshold is reached or exceeded, the corresponding
>    events are generated.
>
>    The address pool high threshold event will be reported when the
>    address pool reaches a high water mark as defined by the operator.
>    This will sever as an indication that the operator might have to add
>    more addresses to the pool or an indication that the subsequent users
>    may be denied NAT translation mappings.
>
>    The address and port mapping high threshold event is generated, when
>    the number of ports in the configured address pool has reached a
>    configured threshold.
>
>    The per-user address and port mapping high threshold is generated
>    when a single user uses more address and port mapping than a
>    configured threshold.
>
> +---------------------------------------------------------+--------+
>    |              Threshold Exceeded Event Name              | Values |
> +---------------------------------------------------------+--------+
>    |            Address pool high threshold event            |      1 |
>    |             Address pool low threshold event            |      2 |
>    |      Address and port mapping high threshold event      |      3 |
>    |  Address and port mapping per user high threshold event |      4 |
>    |       Global Address mapping high threshold event       |      5 |
> +---------------------------------------------------------+--------+
>
>                       Table 4: Threshold event table
>
> 5.6.  Templates for NAT Events
>
>    The following is the template of events that will have to logged.
> ^^^^^^^^^^^^^^^^^^^
>
> SD: I think this is a nit, but the sentence is garbled. "will be logged"?
>
>    The events below are identified at the time of this writing but the
>    events are expandable.  Depending on the implementation and
>    ^^^^^^^^^^^^^^^^^^^^^
> SD: this is a nit, but "set of events is extensible", I think.
>
> [Senthil] Agree. (to both comments).

Thanks,

>    configuration various IE's specified can be included or ignored.
>
> 5.6.1.  NAT44 create and delete session events
>
>    These events will be generated when a NAT44 session is created or
>    deleted.  The template will be the same, the natEvent will indicate
>    whether it is a create or a delete event.  The following is a
>    template of the event.
>
>    The destination address and port information is optional as required
>    by [RFC6888].  However, when the destination information is
>    suppressed, the session log event contains the same information as
>    the BIB event.  In such cases, the NAT device SHOULD NOT send both
>    BIB and session events.
>
> +----------------------------------+-------------+-----------+
>       |            Field Name            | Size (bits) | Mandatory |
> +----------------------------------+-------------+-----------+
>       |            timeStamp             |          64 |    Yes    |
>       |          natInstanceID           |          32 |     No    |
>       |       vlanID/ingressVRFID        |          32 |     No    |
>       |        sourceIPv4Address         |          32 |    Yes    |
>       |     postNATSourceIPv4Address     |          32 |    Yes    |
>       |        protocolIdentifier        |           8 |    Yes    |
>       |       sourceTransportPort        |          16 |    Yes    |
>       |   postNAPTsourceTransportPort    |          16 |    Yes    |
>       |      destinationIPv4Address      |          32 |     No    |
>       |  postNATDestinationIPv4Address   |          32 |     No    |
>       |     destinationTransportPort     |          16 |     No    |
>       | postNAPTdestinationTransportPort |          16 |     No    |
>       |       internalAddressRealm       |           8 |     No    |
>       |       externalAddressRealm       |           8 |     No    |
>       |             natEvent             |           8 |    Yes    |
> +----------------------------------+-------------+-----------+
>
>                Table 5: NAT44 Session delete/create template
>
> 5.6.2.  NAT64 create and delete session events
>
>    These events will be generated when a NAT64 session is created or
>    deleted.  The following is a template of the event.
>
> +----------------------------------+-------------+-----------+
>       |            Field Name            | Size (bits) | Mandatory |
> +----------------------------------+-------------+-----------+
>       |            timeStamp             |          64 |    Yes    |
>       |          natInstanceID           |          32 |     No    |
>       |       vlanID/ingressVRFID        |          32 |     No    |
>       |        sourceIPv6Address         |         128 |    Yes    |
>       |     postNATSourceIPv4Address     |          32 |    Yes    |
>       |        protocolIdentifier        |           8 |    Yes    |
>       |       sourceTransportPort        |          16 |    Yes    |
>       |   postNAPTsourceTransportPort    |          16 |    Yes    |
>       |      destinationIPv6Address      |         128 |     No    |
>       |  postNATDestinationIPv4Address   |          32 |     No    |
>       |     destinationTransportPort     |          16 |     No    |
>       | postNAPTdestinationTransportPort |          16 |     No    |
>       |       internalAddressRealm       |           8 |     No    |
>       |       externalAddressRealm       |           8 |     No    |
>       |             natEvent             |           8 |    Yes    |
> +----------------------------------+-------------+-----------+
>
>             Table 6: NAT64 session create/delete event template
>
> 5.6.3.  NAT44 BIB create and delete events
>
>    These events will be generated when a NAT44 Bind entry is created or
>    deleted.  The following is a template of the event.
>
> +-----------------------------+-------------+-----------+
>          |          Field Name         | Size (bits) | Mandatory |
> +-----------------------------+-------------+-----------+
>          |          timeStamp          |          64 | Yes    |
>          |        natInstanceID        |          32 | No    |
>          |     vlanID/ingressVRFID     |          32 | No    |
>          |      sourceIPv4Address      |          32 | Yes    |
>          |   postNATSourceIPv4Address  |          32 | Yes    |
>          |      protocolIdentifier     |           8 | No    |
>          |     sourceTransportPort     |          16 | No    |
>          | postNAPTsourceTransportPort |          16 | No    |
>          |     internalAddressRealm    |           8 | No    |
>          |     externalAddressRealm    |           8 | No    |
>          |           natEvent          |           8 | Yes    |
> +-----------------------------+-------------+-----------+
>
>               Table 7: NAT44 BIB create/delete event template
>
> 5.6.4.  NAT64 BIB create and delete events
>
>    These events will be generated when a NAT64 Bind entry is created or
>    deleted.  The following is a template of the event.
>
> +-----------------------------+-------------+-----------+
>          |          Field Name         | Size (bits) | Mandatory |
> +-----------------------------+-------------+-----------+
>          |          timeStamp          |          64 | Yes    |
>          |        natInstanceID        |          32 | No    |
>          |     vlanID/ingressVRFID     |          32 | No    |
>          |      sourceIPv6Address      |         128 | Yes    |
>          |   postNATSourceIPv4Address  |          32 | Yes    |
>          |      protocolIdentifier     |           8 | No    |
>          |     sourceTransportPort     |          16 | No    |
>          | postNAPTsourceTransportPort |          16 | No    |
>          |     internalAddressRealm    |           8 | No    |
>          |     externalAddressRealm    |           8 | No    |
>          |           natEvent          |           8 | Yes    |
> +-----------------------------+-------------+-----------+
>
>               Table 8: NAT64 BIB create/delete event template
>
> 5.6.5.  Addresses Exhausted event
>
>    This event will be generated when a NAT device runs out of global
>    IPv4 addresses in a given pool of addresses. Typically, this event
>    would mean that the NAT device wont be able to create any new
>                                   ^^^^
> SD: "won't"
>
> [Senthil] Ok.

Thanks,

>
>    translations until some addresses/ports are freed.  This event SHOULD
>    be rate limited as many packets hitting the device at the same time
>    will trigger a burst of addresses exhausted events.
>
>    The following is a template of the event.  Note that either the NAT
>    pool name or the nat pool identifier should be logged, but not both.
>
> SD: I lack understanding, but I didn't see anything that looked like a 
> NAT pool name in the template. Did I miss something?
>
> [Senthil] We decided not to use a string like a pool name instead use 
> a poolID, which is a unique identifier for each pool name. The reason 
> being that the logs could become fairly large
> If we have to carry the names and some of the NAT engines implement 
> this in the hardware that lacks the string processing capability.

OK, that helps. I'm understanding that a different template might have 
included a pool name, but not a poolID, is that right?

I'm somewhat uneasy about the "either should be logged, but not both" text.

Same question as usual - is this an RFC 2119 SHOULD that helps with 
interoperation, or is this about an implementation choice?

If it's an RFC 2119 SHOULD, robust collectors will need to do something 
if a log arrives with both a pool name and a poolID. If it's a MUST, a 
collector wouldn't accept the log (however the collector would decide to 
do that).

If it's not an RFC 2119 SHOULD, but just implementation guidance, the 
explanation you provided would be more helpful (something like "could 
include a pool name, but some NAT engines are implemented in hardware 
that lacks string processing capability, and these are permitted to 
substitute a poolID. There's no reason to provide both a pool name and a 
poolID").

> +---------------+-------------+-----------+
>                 |   Field Name  | Size (bits) | Mandatory |
> +---------------+-------------+-----------+
>                 |   timeStamp   |          64 |    Yes |
>                 | natInstanceID |          32 |     No |
>                 |    natEvent   |           8 |    Yes |
>                 |   natPoolID   |          32 |    Yes |
> +---------------+-------------+-----------+
>
>                  Table 9: Address Exhausted event template
>
> 5.6.6.  Ports Exhausted event
>
>    This event will be generated when a NAT device runs out of ports for
>    a global IPv4 address.  Port exhaustion shall be reported per
>    protocol (UDP, TCP etc).  This event SHOULD be rate limited as many
>    packets hitting the device at the same time will trigger a burst of
>    port exhausted events.
>
>    The following is a template of the event.
>
> +--------------------------+-------------+-----------+
>           |        Field Name        | Size (bits) | Mandatory |
> +--------------------------+-------------+-----------+
>           |        timeStamp         |          64 | Yes    |
>           |      natInstanceID       |          32 | No    |
>           |         natEvent         |           8 | Yes    |
>           | postNATSourceIPv4Address |          32 | Yes    |
>           |    protocolIdentifier    |           8 | Yes    |
> +--------------------------+-------------+-----------+
>
>                  Table 10: Ports Exhausted event template
>
> 5.6.7.  Quota exceeded events
>
>    This event will be generated when a NAT device cannot allocate
>    resources as a result of an administratively defined policy.  The
>    quota exceeded event templates are described below
>                                                      ^
> SD: missing period
> [Senthil] Ok.

Thanks,

> 5.6.7.1.  Maximum session entries exceeded
>
>    The maximum session entries exceeded is generated when the
>    administratively configured limit is reached.  The following is the
>    template of the event.
>
> +-----------------+-------------+-----------+
>                |    Field Name   | Size (bits) | Mandatory |
> +-----------------+-------------+-----------+
>                |    timeStamp    |          64 |    Yes |
>                |  natInstanceID  |          32 |     No |
>                |     natEvent    |           8 |    Yes |
>                |  natLimitEvent  |          32 |    Yes |
>                | configuredLimit |          32 |    Yes |
> +-----------------+-------------+-----------+
>
>              Table 11: Session Entries Exceeded event template
>
> 5.6.7.2.  Maximum BIB entries exceeded
>
>    The maximum BIB entries exceeded is generated when the
>    administratively configured limit is reached.  The following is the
>    template of the event.
>
> +-----------------+-------------+-----------+
>                |    Field Name   | Size (bits) | Mandatory |
> +-----------------+-------------+-----------+
>                |    timeStamp    |          64 |    Yes |
>                |  natInstanceID  |          32 |     No |
>                |     natEvent    |           8 |    Yes |
>                |  natLimitEvent  |          32 |    Yes |
>                | configuredLimit |          32 |    Yes |
> +-----------------+-------------+-----------+
>
>                Table 12: BIB Entries Exceeded event template
>
> 5.6.7.3.  Maximum entries per user exceeded
>
>    This event is generated when a single user reaches the
>    administratively configured limit.  The following is the template of
>    the event.
>
> +---------------------+-------------+---------------+
>            |      Field Name     | Size (bits) | Mandatory   |
> +---------------------+-------------+---------------+
>            |      timeStamp      |          64 | Yes      |
>            |    natInstanceID    |          32 | No      |
>            |       natEvent      |           8 | Yes      |
>            |    natLimitEvent    |          32 | Yes      |
>            |   configuredLimit   |          32 | Yes      |
>            | vlanID/ingressVRFID |          32 | No      |
>            |  sourceIPv4 address |          32 | Yes for NAT44 |
>            |  sourceIPv6 address |         128 | Yes for NAT64 |
> +---------------------+-------------+---------------+
>
>             Table 13: Per-user Entries Exceeded event template
>
> 5.6.7.4.  Maximum active host or subscribers exceeded
>
>    This event is generated when the number of allowed hosts or
>    subscribers reaches the administratively configured limit.  The
>    following is the template of the event.
>
> +-----------------+-------------+-----------+
>                |    Field Name   | Size (bits) | Mandatory |
> +-----------------+-------------+-----------+
>                |    timeStamp    |          64 |    Yes |
>                |  natInstanceID  |          32 |     No |
>                |     natEvent    |           8 |    Yes |
>                |  natLimitEvent  |          32 |    Yes |
>                | configuredLimit |          32 |    Yes |
> +-----------------+-------------+-----------+
>
>         Table 14: Maximum hosts/subscribers Exceeded event template
>
> 5.6.7.5.  Maximum fragments pending reassembly exceeded
>
>    This event is generated when the number of fragments pending
>    reassembly reaches the administratively configured limit.  The
>    following is the template of the event.
>
> +----------------------+-------------+---------------+
>           |      Field Name      | Size (bits) | Mandatory   |
> +----------------------+-------------+---------------+
>           |      timeStamp       |          64 | Yes      |
>           |    natInstanceID     |          32 | No      |
>           |       natEvent       |           8 | Yes      |
>           |    natLimitEvent     |          32 | Yes      |
>           |   configuredLimit    |          32 | Yes      |
>           | internalAddressRealm |           8 | Yes      |
>           | vlanID/ingressVRFID  |          32 | No      |
>           |  sourceIPv4 address  |          32 | Yes for NAT44 |
>           |  sourceIPv6 address  |         128 | Yes for NAT64 |
> +----------------------+-------------+---------------+
>
>        Table 15: Maximum fragments pending reassembly Exceeded event
>                                  template
>
> 5.6.8.  Threshold reached events
>
>    This event will be generated when a NAT device reaches a operator
>    configured threshold when allocating resources.  The threshold
>    reached events are described in the section above.  The following is
>    a template of the individual events.
>
> 5.6.8.1.  Address pool high or low threshold reached
>
>    This event is generated when the high or low threshold is reached for
>    the address pool.  The template is the same for both high and low
>    threshold events
>
> +-------------------+-------------+-----------+
>               |     Field Name    | Size (bits) | Mandatory |
> +-------------------+-------------+-----------+
>               |     timeStamp     |          64 | Yes    |
>               |   natInstanceID   |          32 | No    |
>               |      natEvent     |           8 | Yes    |
>               | natThresholdEvent |          32 | Yes    |
>               |     natPoolID     |          32 | Yes    |
>               |  configuredLimit  |          32 | Yes    |
> +-------------------+-------------+-----------+
>
>      Table 16: Address pool high/low threshold reached event template
>
> 5.6.8.2.  Address and port high threshold reached
>
>    This event is generated when the high threshold is reached for the
>    address pool and ports.
>
> +-------------------+-------------+-----------+
>               |     Field Name    | Size (bits) | Mandatory |
> +-------------------+-------------+-----------+
>               |     timeStamp     |          64 | Yes    |
>               |   natInstanceID   |          32 | No    |
>               |      natEvent     |           8 | Yes    |
>               | natThresholdEvent |          32 | Yes    |
>               |  configuredLimit  |          32 | Yes    |
> +-------------------+-------------+-----------+
>
>        Table 17: Address port high threshold reached event template
>
> 5.6.8.3.  Per-user Address and port high threshold reached
>
>    This event is generated when the high threshold is reached for the
>    per-user address pool and ports.
>
> +---------------------+-------------+---------------+
>            |      Field Name     | Size (bits) | Mandatory   |
> +---------------------+-------------+---------------+
>            |      timeStamp      |          64 | Yes      |
>            |    natInstanceID    |          32 | No      |
>            |       natEvent      |           8 | Yes      |
>            |  natThresholdEvent  |          32 | Yes      |
>            |   configuredLimit   |          32 | Yes      |
>            | vlanID/ingressVRFID |          32 | No      |
>            |  sourceIPv4 address |          32 | Yes for NAT44 |
>            |  sourceIPv6 address |         128 | Yes for NAT64 |
> +---------------------+-------------+---------------+
>
>    Table 18: Per-user Address port high threshold reached event template
>
> 5.6.8.4.  Global Address mapping high threshold reached
>
>    This event is generated when the high is reached for the per-user
>    address pool and ports.  This is generated only by NAT devices that
>    use a address pooling behavior of paired.
>
> +---------------------+-------------+-----------+
>              |      Field Name     | Size (bits) | Mandatory |
> +---------------------+-------------+-----------+
>              |      timeStamp      |          64 | Yes    |
>              |    natInstanceID    |          32 | No    |
>              |       natEvent      |           8 | Yes    |
>              |  natThresholdEvent  |          32 | Yes    |
>              |   configuredLimit   |          32 | Yes    |
>              | vlanID/ingressVRFID |          32 | No    |
> +---------------------+-------------+-----------+
>
>        Table 19: Global Address mapping high threshold reached event
>                                  template
>
> 5.6.9.  Address binding create and delete events
>
>    These events will be generated when a NAT device binds a local
>    address with a global address and when the global address is freed.
>    This binding event happens when the first packet of the first flow
>    from a host in the private realm.
>
> +--------------------------------+-------------+---------------+
>      |           Field Name           | Size (bits) | Mandatory   |
> +--------------------------------+-------------+---------------+
>      |           timeStamp            |          64 | Yes      |
>      |         natInstanceID          |          32 |       No      |
>      |            natEvent            |           8 | Yes      |
>      |       sourceIPv4 address       |          32 | Yes for NAT44 |
>      |       sourceIPv6 address       |         128 | Yes for NAT64 |
>      | Translated Source IPv4 Address |          32 | Yes      |
> +--------------------------------+-------------+---------------+
>
>                   Table 20: NAT Address Binding template
>
> 5.6.10.  Port block allocation and de-allocation
>
>    This event will be generated when a NAT device allocates/de-allocates
>    ports in a bulk fashion, as opposed to allocating a port on a per
>    flow basis.
>
>    portRangeStart represents the starting value of the range.
>
>    portRangeEnd represents the ending value of the range.
>
>    NAT devices would do this in order to reduce logs and potentially to
>    limit the number of connections a subscriber is allowed to use.  In
>    the following Port Block allocation template, the portRangeStart and
>    portRangeEnd must be specified.
>
>
> Sivakumar & Penno        Expires August 15, 2014               [Page 17]
>
> Internet-Draft          IPFIX IEs for NAT logging February 2014
>
>    It is up to the implementation to choose to consolidate log records
>    in case two consecutive port ranges for the same user are allocated
>    or freed.
>
> +--------------------------------+-------------+---------------+
>      |           Field Name           | Size (bits) | Mandatory   |
> +--------------------------------+-------------+---------------+
>      |           timeStamp            |          64 | Yes      |
>      |         natInstanceID          |          32 |       No      |
>      |            natEvent            |           8 | Yes      |
>      |       sourceIPv4 address       |          32 | Yes for NAT44 |
>      |       sourceIPv6 address       |         128 | Yes for NAT64 |
>      | Translated Source IPv4 Address |          32 | Yes      |
>      |         portRangeStart         |          16 | Yes      |
>      |          portRangeEnd          |          16 |       No      |
> +--------------------------------+-------------+---------------+
>
>             Table 21: NAT Port Block Allocation event template
>
> 6.  Encoding
>
> 6.1.  IPFIX
>
>    This document uses IPFIX as the encoding mechanism to describe the
>    logging of NAT events.  However, the information that should be
>    logged SHOULD be the same irrespective of what kind of encoding
>    scheme is used.  IPFIX is chosen because is it an IETF standard that
>    meets all the needs for a reliable logging mechanism. IPFIX provides
>    the flexibility to the logging device to define the data sets that it
>    is logging.  The IEs specified for logging MUST be the same
>    irrespective of the encoding mechanism used.
>
> 7.  Acknowledgements
>
>    Thanks to Dan Wing, Selvi Shanmugam, Mohamed Boucadir, Jacni Qin
>    Ramji Vaithianathan, Simon Perreault, Jean-Francois Tremblay, Paul
>    Aitken and Julia Renouard for their review and comments.
>
> 8.  IANA Considerations
>
>    The following information elements are requested from IANA IPFIX
>    registry.
>
>    natInstanceId
>
>    externalAddressRealm
>
>    natLimitEvent
>
> 9.  Management Considerations
>
>    This section considers requirements for management of the log system
>    to support logging of the events described above.  It first covers
>    requirements applicable to log management in general. Any additional
>    standardization required to fullfil these requirements is out of
>    scope of the present document.  Some management considerations is
>    covered in [I-D.behave-syslog-nat-logging].  This document covers the
>    additional considerations.
>
> 9.1.  Ability to collect events from multiple NAT devices
>
>    An IPFIX collector should be able to collect events from multiple NAT
>    devices and be able to decipher events based on the sourceID in the
>    IPFIX header.
>
> 9.2.  Ability to suppress events
>
>    The exhaustion events can be overwhelming during traffic bursts and
>    hence should be handled by the NAT devices to rate limit them before
>    sending them to the collectors.  For eg. when the port exhaustion
>    happens during bursty conditions, instead of sending a port
>    exhaustion event for every packet, the exhaustion events should be
>    rate limited by the NAT device.
>
> 10.  Security Considerations
>
>    None.
>
> 11.  References
>
> 11.1.  Normative References
>
>    [RFC2119]  Bradner, S., "Key words for use in RFCs to Indicate
>               Requirement Levels", BCP 14, RFC 2119, March 1997.
>
>    [RFC2663]  Srisuresh, P. and M. Holdrege, "IP Network Address
>               Translator (NAT) Terminology and Considerations", RFC
>               2663, August 1999.
>
>    [RFC4787]  Audet, F. and C. Jennings, "Network Address Translation
>               (NAT) Behavioral Requirements for Unicast UDP", BCP 127,
>               RFC 4787, January 2007.
>
>    [RFC5382]  Guha, S., Biswas, K., Ford, B., Sivakumar, S., and P.
>               Srisuresh, "NAT Behavioral Requirements for TCP", BCP 142,
>               RFC 5382, October 2008.
>
>    [RFC6146]  Bagnulo, M., Matthews, P., and I. van Beijnum, "Stateful
>               NAT64: Network Address and Protocol Translation from IPv6
>               Clients to IPv4 Servers", RFC 6146, April 2011.
>
>    [RFC6302]  Durand, A., Gashinsky, I., Lee, D., and S. Sheppard,
>               "Logging Recommendations for Internet-Facing Servers", BCP
>               162, RFC 6302, June 2011.
>
>    [RFC6888]  Perreault, S., Yamagata, I., Miyakawa, S., Nakagawa, A.,
>               and H. Ashida, "Common Requirements for Carrier-Grade NATs
>               (CGNs)", BCP 127, RFC 6888, April 2013.
>
> 11.2.  Informative References
>
>    [I-D.ietf-behave-syslog-nat-logging]
>               Chen, Z., Zhou, C., Tsou, T., and T. Taylor, "Syslog
>               Format for NAT Logging", draft-ietf-behave-syslog-nat-
>               logging-06 (work in progress), January 2014.
>
>    [IPFIX-IANA]
>               IANA, "IPFIX Information Elements registry",
> <http://www.iana.org/assignments/ipfix>.
>
>    [RFC5101bis]
>               Claise, B. and B. Trammel, "Specification of the IP Flow
>               Information eXport (IPFIX) Protocol for the Exchange of
>               Flow Information", July 2013.
>
>    [RFC5102bis]
>               Claise, B. and B. Trammel, "Information Model for IP Flow
>               Information eXport (IPFIX)", February 2013.
>
>    [RFC5470]  Sadasivan, G., Brownlee, N., Claise, B., and J. Quittek,
>               "Architecture for IP Flow Information Export", RFC 5470,
>               March 2009.
>
> Authors' Addresses
>
>    Senthil Sivakumar
>    Cisco Systems
>    7100-8 Kit Creek Road
>    Research Triangle Park, North Carolina  27709
>    USA
>
>    Phone: +1 919 392 5158
>
>    Renaldo Penno
>    Cisco Systems
>    170 W Tasman Drive
>    San Jose, California  95035
>    USA
>
>    Email: repenno@cisco.com
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
> Sivakumar & Penno        Expires August 15, 2014               [Page 21]


--------------030908080302000709080908
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    <div class="moz-cite-prefix">On 05/02/2014 02:20 PM, Senthil
      Sivakumar (ssenthil) wrote:<br>
    </div>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <div>Hi Spencer, </div>
      <div>Thanks for the thorough review. </div>
      <div>Please see inline for [Senthil]. If you agree, I will submit
        another version fixing all the issues raised and agreed upon. I
        will wait for your response.</div>
    </blockquote>
    <br>
    Hi, Senthil,<br>
    <br>
    Thanks for being responsive!<br>
    <br>
    Just as a high-order bit, many of the questions I asked are whether
    the draft uses "required" to mean "this is the way it works" -
    there's a difference between "the sender transmits a log" and "the
    sender is required to transmit a log". Does that make sense?<br>
    <br>
    Ths draft says it uses requirements language as per RFC 2119, and
    RFC 2119 says <br>
    <br>
    <meta http-equiv="content-type" content="text/html;
      charset=windows-1252">
    6. Guidance in the use of these Imperatives<br>
    <br>
       Imperatives of the type defined in this memo must be used with
    care<br>
       and sparingly.  In particular, they MUST only be used where it is<br>
       actually required for interoperation or to limit behavior which
    has<br>
       potential for causing harm (e.g., limiting retransmisssions)  For<br>
       example, they must not be used to try to impose a particular
    method<br>
       on implementors where the method is not required for<br>
       interoperability.<br>
    <br>
    It's also worth mentioning that RFC 2119 is silent on case for
    requirements language, your requirements terminology section only
    shows upper case examples, and most of the cases I'm asking about
    are in lower case, which makes it less clear whether you intend
    "require" to be an RFC 2119 requirement word or not. This is a
    continuing source of controversy in the IETF, especially during
    cross-area review - my suggestion is that you either change the
    requirements language statement to include a statement about whether
    lower-case versions are intended as requirements language, or don't
    use the lower-case terms in the document.<br>
    <br>
    I'll try to be clear in my detailed comments, but that's often what
    I'm trying to get at.<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <div>Thanks</div>
      <div>Senthil</div>
      <div><br>
      </div>
      <span id="OLK_SRC_BODY_SECTION">
        <div style="font-family:Calibri; font-size:11pt;
          text-align:left; color:black; BORDER-BOTTOM: medium none;
          BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT:
          0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;
          BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
          <span style="font-weight:bold">From: </span>Spencer Dawkins
          &lt;<a moz-do-not-send="true"
            href="mailto:spencerdawkins.ietf@gmail.com">spencerdawkins.ietf@gmail.com</a>&gt;<br>
          <span style="font-weight:bold">Date: </span>Thursday, May 1,
          2014 4:25 PM<br>
          <span style="font-weight:bold">To: </span>"<a
            moz-do-not-send="true"
            href="mailto:draft-ietf-behave-ipfix-nat-logging@tools.ietf.org">draft-ietf-behave-ipfix-nat-logging@tools.ietf.org</a>"
          &lt;<a moz-do-not-send="true"
            href="mailto:draft-ietf-behave-ipfix-nat-logging@tools.ietf.org">draft-ietf-behave-ipfix-nat-logging@tools.ietf.org</a>&gt;<br>
          <span style="font-weight:bold">Cc: </span>"<a
            moz-do-not-send="true" href="mailto:behave@ietf.org">behave@ietf.org</a>"
          &lt;<a moz-do-not-send="true" href="mailto:behave@ietf.org">behave@ietf.org</a>&gt;<br>
          <span style="font-weight:bold">Subject: </span>AD Evaluation
          of draft-ietf-behave-ipfix-nat-logging-03<br>
          <span style="font-weight:bold">Resent-From: </span>&lt;<a
            moz-do-not-send="true"
            href="mailto:draft-alias-bounces@tools.ietf.org">draft-alias-bounces@tools.ietf.org</a>&gt;<br>
          <span style="font-weight:bold">Resent-To: </span>&lt;<a
            moz-do-not-send="true" href="mailto:repenno@cisco.com">repenno@cisco.com</a>&gt;,
          Senthil Sivakumar &lt;<a moz-do-not-send="true"
            href="mailto:ssenthil@cisco.com">ssenthil@cisco.com</a>&gt;<br>
          <span style="font-weight:bold">Resent-Date: </span>Thursday,
          May 1, 2014 4:26 PM<br>
        </div>
        <div><br>
        </div>
        <div>
          <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
              New,Courier,monospace">Dear
              draft-ietf-behave-ipfix-nat-logging Authors,<br>
              <br>
              I've completed my AD evaluation for this draft. I found
              some things I'd like to see changed before proceeding, but
              most are editorial. Please take a look, and let me know
              what you think.<br>
              <br>
              My notes follow ... you should be able to find my
              questions and comments by searching for "SD:".<br>
              <br>
              Thanks,<br>
              <br>
              Spencer<br>
              <br>
              In the Abstract<br>
              <br>
                 NAT devices are required to log events like creation
              and deletion of<br>
                                 ^^^^^^^^<br>
              SD: Is this required, like, legally required, or ? Is it
              more like "Operators need NAT devices to log events ..."?</font></div>
        </div>
      </span>
      <div>[Senthil] : It is the later, the network operators require
        the NAT devices to be able to log events.</div>
    </blockquote>
    <br>
    We don't usually include requirements language in the Abstract (that
    happens later, which is fine in the document body).<br>
    <br>
    The longer I look at this, the more I think it's something like
    "Operators expect NAT devices to log events".<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <span id="OLK_SRC_BODY_SECTION">
        <div>
          <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
              New,Courier,monospace"><br>
                 translations and information about the resources it is
              managing.  The<br>
                 logs are required in many cases to identify an attacker
              or a host<br>
                 that was used to launch malicious attacks and/or for
              various other<br>
                 purposes of accounting.  Since there is no standard way
              of logging<br>
                 this information, different NAT devices behave
              differently and hence<br>
                                            
              ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^<br>
              SD: Is this "different NAT devices log this information
              differently"? </font></div>
        </div>
      </span>
      <div bgcolor="#FFFFFF" text="#000000">[Senthil] Correct, as the
        sentence says, "Since there is no standard way…", each NAT
        device logs information in its own proprietary format.<font
          face="Courier New,Courier,monospace"><br>
        </font></div>
    </blockquote>
    <br>
    I'm just trying to make sure the reader understands what you mean by
    "behave differently" - NAT devices also behave differently when
    NATting.  I had to guess at the meaning. Maybe everyone else will
    understand?<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
          New,Courier,monospace">
             it is difficult to expect a consistent behavior.  The lack
          of a<br>
             consistent way makes it difficult to write the collector
          applications<br>
             that would receive this data and process it to present
          useful<br>
             information.  This document describes the information that
          is<br>
             required to be logged by the NAT devices.<br>
             ^^^^^^^^^^^^^^^^^^^^^^^^ <br>
          SD: Same as previous question - is this "logged by"?</font></div>
      <span id="OLK_SRC_BODY_SECTION">
        <div>
        </div>
      </span>
      <div><br>
      </div>
      <div>[Senthil] If a NAT device is logging events, these are the
        requirements that a NAT device should adhere to.</div>
    </blockquote>
    <br>
    I know this seems tedious, but I'm not able to map what you provided
    as explanation onto the text you're explaining. What I'm seeing in
    the text is<br>
    <br>
    A NAT MUST log this information<br>
    <br>
    and what I'm seeing in your explanation is<br>
    <br>
    IF a NAT is is logging information, here's how the NAT SHOULD log
    information.<br>
    <br>
    I'm guessing that what you're saying is really "this document
    describes the information that logging NAT devices produce". <br>
    <br>
    This doesn't matter yet (you're still in the abstract, which
    shouldn't be providing requirements anyway), but in the body of the
    document, it needs to be clear.<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <span id="OLK_SRC_BODY_SECTION">
        <div>
          <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
              New,Courier,monospace">2.  Introduction<br>
              <br>
                 The IPFIX Protocol [RFC5101bis] defines a generic push
              mechanism for<br>
                 exporting information and events.  The IPFIX
              Information Model<br>
                 [IPFIX-IANA] defines a set of standard Information
              Elements (IEs)<br>
                 which can be carried by the IPFIX protocol.  This
              document details<br>
                 the IPFIX Information Elements(IEs) that are required
              for logging by<br>
                 a NAT device.  The document will specify the format of
              the IE's that<br>
                 are required to be logged by the NAT device and all the
              optional<br>
                     ^^^^^^^^^^^^^^^^^^^^^<br>
              SD: Now that we're in the document body, if this is
              required, shouldn't there be a reference to where the
              requirements are stated?</font></div>
        </div>
      </span>
      <div>[Senthil] This is the document that is specifying those
        requirements. Do you have any other suggestions of wording
        instead of "required by", would it be fine if I change the
        sentence from</div>
      <div bgcolor="#FFFFFF" text="#000000">"required to be logged" to
        "SHOULD be logged"?<font face="Courier New,Courier,monospace"><br>
        </font></div>
    </blockquote>
    <br>
    Sorry, my first set of comments was bogus. What triggered my
    comments was the use of lower-case terms from RFC 2119 (see my
    explanation above).<br>
    <br>
    This could be "are REQUIRED" (the RFC 2119 requirements language you
    said you're using), or "are required" (if you change your paragraph
    about requirements language to say that case doesn't matter).<br>
    <br>
    But "REQUIRED" is "MUST", so changing to "SHOULD" would be a change
    in your intended meaning.<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite"><br>
      <span id="OLK_SRC_BODY_SECTION">
        <div>
          <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
              New,Courier,monospace">
                 This document and [I-D.behave-syslog-nat-logging] are
              provided in<br>
                 order to standardize the events and parameters to be
              recorded, using<br>
                 IPFIX [RFC5101bis] and SYSLOG [RFC5424]respectively.<br>
            </font></div>
        </div>
      </span></blockquote>
    <br>
    I'm sorry I missed this question the first time. Is there a
    relationship with the MIB revision?<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite"><span id="OLK_SRC_BODY_SECTION">
        <div>
          <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
              New,Courier,monospace">
              3.  Scope<br>
              <br>
                 This document provides the information model to be used
              for logging<br>
                 the NAT devices including Carrier Grade NAT (CGN)
              events.  This<br>
                                
              ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^<br>
              SD: This sentence seems somewhat turned around - "logging
              events", not "logging the NAT devices".</font></div>
        </div>
      </span>
      <div bgcolor="#FFFFFF" text="#000000">[Senthil] Agree, I will
        change this to "logging the NAT events". <font face="Courier
          New,Courier,monospace"><br>
        </font></div>
    </blockquote>
    <br>
    Thanks.<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
          New,Courier,monospace">
             document focuses exclusively on the specification of IPFIX
          IE's.<br>
             This document does not provide guidance on the transport
          protocol<br>
             like TCP, UDP or SCTP that is to be used to log NAT
          events.  The log<br>
             events SHOULD NOT be lost but the choice of the actual
          transport<br>
             protocol is beyond the scope of this document.<br>
          <br>
          SD: I'm not understanding why this last sentence is needed,
          especially with a normative requirement for what you do when
          you are doing something outside the scope of the document ...</font></div>
      <span id="OLK_SRC_BODY_SECTION">
        <div>
        </div>
      </span>
      <div>[Senthil] Are you objecting to the second part of the last
        sentence "the choice of actual transport…", I think the
        requirement is that the LOG events should not be lost is valid.</div>
    </blockquote>
    <br>
    I'm sorry, my question wasn't clear. What I intended to say was that
    I was confused because the text said "not providing guidance on the
    choice of a transport protocol", but then provided a requirement
    about the implications of that choice (using a SHOULD).<br>
    <br>
    So let me try to be clearer. I think what you're saying is <br>
    <br>
    - you can use any transport protocol, but you SHOULDn't lose
    anything<br>
    <br>
    I'm thinking this may be underspecified, although I don't know what
    IPFIX usually expects from transport protocols, so please be
    patient.<br>
    <br>
    First, I'm confused by the SHOULD with no qualification. When is it
    OK to lose LOG events?<br>
    <br>
    Second, you're not giving guidance on selecting a transport
    protocol, but you are giving guidance about expecting a reliable
    data channel, whether MUST be reliable or SHOULD be reliable. Are
    there other transport characteristics that you expect? For instance,
    is in-order delivery assumed? Is duplicate detection by IPFIX
    assumed (if a log arrives twice, does IPFIX notice)?<br>
    <br>
    Third, are IPFIX implementations so transport protocol-agnostic that
    if my NAT device decides to to send logs using SCTP with partial
    reliability, I should expect that to work with any collector that
    implements this specification?<br>
    <br>
    It happens that I co-chaired MEDIACTRL when the specification said
    "TCP or SCTP", and got feedback during AD evaluation that if we
    didn't pick a mandatory to implement transport protocol, that
    wouldn't guarantee interoperation between two standard-conforming
    devices.<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <span id="OLK_SRC_BODY_SECTION">
        <div>
          <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
              New,Courier,monospace"><br>
                 The existing IANA IPFIX IEs registry [IPFIX-IANA]
              already has<br>
                 assignments for many NAT logging events.  For
              convenience, this<br>
                 document uses those same IEs.  However, as stated
              earlier, this<br>
                 document is not defining IPFIX or NetFlow v9 as the
              framework for<br>
                 logging.  Rather, the information contained in these
              elements is<br>
              <br>
              SD: I got lost on "these elements" - is that "the elements
              in the existing registry"</font></div>
        </div>
      </span>
      <div bgcolor="#FFFFFF" text="#000000">[Senthil] Yes. How about
        "Rather, the information elements as defined in the IPFIX-IANA
        registry is within the scope of this document"?<font
          face="Courier New,Courier,monospace"><br>
        </font></div>
    </blockquote>
    <br>
    <font face="Courier New,Courier,monospace">I think that's "are
      within", but yes, that works. Thanks.<br>
      <br>
    </font>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
          New,Courier,monospace">
             within the scope of this document.<br>
          <br>
             This document assumes that the NAT device will use the
          existing IPFIX<br>
             framework to send the log events to the collector.  This
          would mean<br>
             that the NAT device will specify the template that it is
          going to use<br>
             for each of the events.  The templates can be of varying
          length and<br>
             there could be multiple templates that a NAT device could
          use to log<br>
             the events.<br>
          <br>
             The implementation details of the collector application is
          beyond the<br>
             scope of this document.<br>
          <br>
             The optimization of logging the NAT events are left to the<br>
                                                        ^^^<br>
             implementation and are beyond the scope of this document.<br>
                                ^^^<br>
          SD: It's a nit, but those "are"s should be "is"s.</font></div>
      <span id="OLK_SRC_BODY_SECTION">
        <div>
        </div>
      </span>
      <div bgcolor="#FFFFFF" text="#000000">[Senthil] Ok.<font
          face="Courier New,Courier,monospace"><br>
        </font></div>
    </blockquote>
    <br>
    Thanks.<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
          New,Courier,monospace">
          4.  Applicability<br>
          <br>
             NAT logging based on IPFIX uses binary encoding and hence
          is very<br>
             efficient.  IPFIX based logging is recommended for
          environments where<br>
             a high volume of logging is required, for example, where
          per-flow<br>
             logging is needed.  However, IPFIX based logging requires a
          collector<br>
             that processes the binary data and requires a network
          management<br>
             application that converts this binary data to a human
          readable<br>
             format.<br>
          <br>
          5.  Event based logging<br>
          <br>
             An event in a NAT device can be viewed as a happening as it
          relates<br>
                                                         ^^^^^^^^^<br>
          SD: Is this "a state transition"? I found "a happening"
          somewhat odd.</font></div>
      <span id="OLK_SRC_BODY_SECTION">
        <div>
        </div>
      </span>
      <div bgcolor="#FFFFFF" text="#000000">[Senthil] Yes, I can
        rephrase this as "viewed as a state transition as it relates to"
        or "viewed as an action as it relates to", if that is ok.<font
          face="Courier New,Courier,monospace"><br>
        </font></div>
    </blockquote>
    <br>
    If "a state transition" is correct, I'd prefer that (if it's correct
    :-) ).<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
          New,Courier,monospace">
             to the management of NAT resources.  The creation and
          deletion of NAT<br>
             sessions and bindings are examples of events as it results
          in the<br>
             resources (addresses and ports) being allocated or freed. 
          The events<br>
             can happen either through the processing of data packets
          flowing<br>
             through the NAT device or through an external entity
          installing<br>
             policies on the NAT router or as a result of an
          asynchronous event<br>
             like a timer.  The list of events are provided in Section
          4.1.  Each<br>
             of these events SHOULD be logged, unless they are
          administratively<br>
             prohibited.  A NAT device MAY log these events to multiple
          collectors<br>
             if redundancy is required.  The network administrator will
          specify<br>
             the collectors to which the log records are to be sent.<br>
          <br>
             A collector may receive NAT events from multiple CGN
          devices and<br>
             should be able to distinguish between the devices.  Each
          CGN device<br>
             ^^^^^^<br>
          SD: I'm not sure why this isn't a SHOULD, or even a MUST.<br>
          <br>
             should have a unique source ID to identify themselves.  The
          source ID<br>
             ^^^^^^<br>
          SD: Again, I'm not sure why this isn't a SHOULD, or even a
          MUST.</font></div>
      <span id="OLK_SRC_BODY_SECTION">
        <div>
        </div>
      </span>
      <div><br>
      </div>
      <div>[Senthil] Well, this is NOT a statement for a NAT device,
        instead it is a collector that some application writer will </div>
      <div bgcolor="#FFFFFF" text="#000000">develop. <font
          face="Courier New,Courier,monospace"><br>
        </font></div>
    </blockquote>
    <br>
    Don't you think you can levy requirements about that on the
    collector? I don't understand. <br>
    <br>
    But beyond that, what I THINK the text is saying, is that multiple
    CGN devices can ("may") send to a single collector, that none of the
    CDN devices have to have a unique source ID to identify themselves
    ("should", but not "must"), and that the collector is still expected
    to be able to distinguish among logs coming from multiple CGNs
    ("should").<br>
    <br>
    Am I misreading this?<br>
    <br>
    If not, do you think that works?<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
          New,Courier,monospace">
             is part of the IPFIX template and data exchange.<br>
          <br>
             Prior to logging any events, the NAT device MUST send the
          template of<br>
             the record to the collector to advertise the format of the
          data<br>
             record that it is using to send the events.  The templates
          can be<br>
             exchanged as frequently as required given the reliability
          of the<br>
             connection.  There SHOULD be a configurable timer for
          controlling the<br>
             template refresh.  NAT device SHOULD combine as many events
          as<br>
             possible in a single packet to effectively utilize the
          network<br>
             bandwidth.<br>
          <br>
          5.1.  Logging of destination information<br>
          <br>
             Logging of destination information in a NAT event has been
          discussed<br>
             in [RFC6302] and [RFC6888].  Logging of destination
          information<br>
             increases the size of each record and increases the need
          for storage<br>
             considerably.  It increases the number of log events
          generated<br>
             because when the same user connects to a different
          destination, it<br>
             results in a log record per destination address.  Logging
          of<br>
             destination information also results in the loss of privacy
          and hence<br>
             should be done with caution.  However, this draft provides
          the<br>
             necessary fields to log the destination information in
          cases where<br>
             they are required to be logged.<br>
          <br>
          5.2.  Information Elements<br>
          <br>
             The templates could contain a subset of the Information
          Elements(IEs)<br>
             shown in Table 1 depending upon the event being logged. 
          For example<br>
             a NAT44 session creation template record will contain,<br>
                                                      ^^^^<br>
          SD: Is this the only possible NAT44 template? If so, fine, but
          if not, perhaps "could contain", or "typically contains"?</font></div>
      <span id="OLK_SRC_BODY_SECTION">
        <div>
        </div>
      </span>
      <div><br>
      </div>
      <div bgcolor="#FFFFFF" text="#000000">[Senthil] Yes, this is all
        the information that a NAT44 need to export as it is the least
        common denominator.<font face="Courier New,Courier,monospace"><br>
        </font></div>
    </blockquote>
    <br>
    My question is whether any other IEs might be added in the future, I
    think. If not, "will" is OK, but "MUST" would be clearer.<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
          New,Courier,monospace">
             {sourceIPv4Adress, postNATSourceIPv4Address,
          destinationIpv4Address,<br>
             postNATDestinationIPv4Address, sourceTransportPort,<br>
             postNAPTSourceTransportPort, destinationTransportPort,<br>
             postNAPTDestTransportPort, internalAddressRealm, natEvent,
          timeStamp}<br>
          <br>
             An example of the actual event data record is shown below -
          in a<br>
             readable form<br>
          <br>
             {192.168.16.1, 201.1.1.100, 207.85.231.104, 207.85.231.104,
          14800,<br>
             1024, 80, 80, 0, 1, 09:20:10:789}<br>
          <br>
             A single NAT device could be exporting multiple templates
          and the<br>
             collector should support receiving multiple templates from
          the same<br>
             source.observationTimeMilliseconds<br>
          <br>
             The following is the table of all the IE's that a CGN
          device would<br>
             need to export the events.  The formats of the IE's and the
          IPFIX IDs<br>
             are listed below.<br>
          <br>
          SD: I noticed that some IEs below have a name that matches <a
            moz-do-not-send="true" class="moz-txt-link-freetext"
href="http://www.iana.org/assignments/ipfix/ipfix.xhtml#ipfix-information-elements">http://www.iana.org/assignments/ipfix/ipfix.xhtml#ipfix-information-elements</a>
          for the same IPFIX ID number, but others do not ("timeStamp"
          here doesn't match "observationTimeMilliseconds", but both are
          IPFIX ID 323, aren't they?) Is there a reason to use names
          that don't match the IANA registry?</font></div>
      <span id="OLK_SRC_BODY_SECTION">
        <div>
        </div>
      </span>
      <div><br>
      </div>
      <div>[Senthil] Good question, in case of timeStamp, I was looking
        for something that already existed in the IPFIX registry rather
        than asking for a new one. However, the terminology of
        "observationTimeMilliseconds" is not the terminology that we use
        in the NAT drafts/rfc's. So I am open to suggestions here. I can
        clarify in the description that is called
        observationTimeMilliSeconds". The other field is
        internalAddressRealm and externalAddresRealm, this is the
        terminology that we used in NAT MIB, syslog and other documents.
        However, when we defined the IPFIX IE, we didn’t stick to the
        same terminology, so I don’t know if I can go and ask the IPFIX
        IANA to change the name. Again I am open to suggestions, the
        dillema is whether I should stick to the existing IPFIX IANA
        terminology or the behave documents terminology.</div>
    </blockquote>
    <br>
    I'm way out of my depth on this one (sorry!).<br>
    <br>
    Fortunately, the next stop for an AD-sponsored IPFIX specification
    is the IPFIX review team. Could you just add a note pointing this
    question out, and asking if they have any suggestions?<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <span id="OLK_SRC_BODY_SECTION">
        <div>
          <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
              New,Courier,monospace">  
              +----------------------------------+--------+-------+---------------+<br>
                 |            Field Name            |   Size |  IANA | 
              Description  |<br>
                 |                                  | (bits) | IPFIX
              |               |<br>
                 |                                  |        |    ID
              |               |<br>
                
              +----------------------------------+--------+-------+---------------+<br>
                 |            timeStamp             |     64 |   323 | 
              System Time  |<br>
                 |                                  |        |      
              |    when the   |<br>
                 |                                  |        |      
              |     event     |<br>
                 |                                  |        |      
              |    occured.   |<br>
                 |          natInstanceId           |     32 |   TBD | 
              NAT Instance |<br>
                 |                                  |        |       |  
              Identifier  |<br>
                 |              vlanID              |     16 |    58 |  
              VLAN ID in  |<br>
                 |                                  |        |      
              |    case of    |<br>
                 |                                  |        |       | 
              overlapping  |<br>
                 |                                  |        |      
              |    networks   |<br>
                 |           ingressVRFID           |     32 |   234 |  
              VRF ID in   |<br>
                 |                                  |        |      
              |    case of    |<br>
                 |                                  |        |       | 
              overlapping  |<br>
                 |                                  |        |      
              |    networks   |<br>
                 |        sourceIPv4Address         |     32 |     8 | 
              Source IPv4  |<br>
                 |                                  |        |      
              |    Address    |<br>
                 |     postNATSourceIPv4Address     |     32 |   225 |  
              Translated  |<br>
                 |                                  |        |       | 
              Source IPv4  |<br>
                 |                                  |        |      
              |    Address    |<br>
                 |        protocolIdentifier        |      8 |     4 |  
              Transport   |<br>
                 |                                  |        |      
              |    protocol   |<br>
                 |       sourceTransportPort        |     16 |     7 | 
              Source Port  |<br>
                 |   postNAPTsourceTransportPort    |     16 |   227 |  
              Translated  |<br>
                 |                                  |        |       | 
              Source port  |<br>
                 |      destinationIPv4Address      |     32 |    12 | 
              Destination  |<br>
                 |                                  |        |       | 
              IPv4 Address |<br>
                 |  postNATDestinationIPv4Address   |     32 |   226 |  
              Translated  |<br>
                 |                                  |        |      
              |      IPv4     |<br>
                 |                                  |        |       | 
              destination  |<br>
                 |                                  |        |      
              |    address    |<br>
                 |     destinationTransportPort     |     16 |    11 | 
              Destination  |<br>
                 |                                  |        |      
              |      port     |<br>
                 | postNAPTdestinationTransportPort |     16 |   228 |  
              Translated  |<br>
                 |                                  |        |       | 
              Destination  |<br>
                 |                                  |        |      
              |      port     |<br>
                 |        sourceIPv6Address         |     27 |   128 | 
              Source IPv6  |<br>
                 |                                  |        |      
              |    address    |<br>
                 |      destinationIPv6Address      |    128 |    28 | 
              Destination  |<br>
                 |                                  |        |       | 
              IPv6 address |<br>
                 |     postNATSourceIPv6Address     |    128 |   281 |  
              Translated  |<br>
                 |                                  |        |       | 
              source IPv6  |<br>
                 |                                  |        |      
              |    addresss   |<br>
                 |  postNATDestinationIPv6Address   |    128 |   282 |  
              Translated  |<br>
                 |                                  |        |       | 
              Destination  |<br>
                 |                                  |        |       | 
              IPv6 address |<br>
                 |       internalAddressRealm       |      8 |   229
              |     Source    |<br>
                 |                                  |        |       |
              Address Realm |<br>
                 |       externalAddressRealm       |      8 |   TBD | 
              Destination  |<br>
                 |                                  |        |       |
              Address Realm |<br>
                 |             natEvent             |      8 |   230 |
              Type of Event |<br>
                 |          portRangeStart          |     16 |   361 |  
              Allocated   |<br>
                 |                                  |        |       |  
              port block  |<br>
                 |                                  |        |      
              |     start     |<br>
                 |           portRangeEnd           |     16 |   362 |  
              Allocated   |<br>
                 |                                  |        |       |  
              Port block  |<br>
                 |                                  |        |      
              |      end      |<br>
                 |            natPoolID             |     32 |   283
              |    NAT pool   |<br>
                 |                                  |        |       |  
              Identifier  |<br>
                 |          natLimitEvent           |     32 |   TBD | 
              Limit event  |<br>
                 |                                  |        |       |  
              identifier  |<br>
                
              +----------------------------------+--------+-------+---------------+<br>
              <br>
                                    Table 1: Template format Table<br>
              <br>
              5.3.  Definition of NAT Events<br>
              <br>
                 The following are the list of NAT events and the
              proposed event<br>
                 values.  The list can be expanded in the future as
              necessary.  The<br>
                 data record will have the corresponding natEvent value
              to identify<br>
                 the event that is being logged.<br>
              <br>
                                 +--------------------------+--------+<br>
                                 |        Event Name        | Values |<br>
                                 +--------------------------+--------+<br>
                                 |   NAT44 Session create   |      1 |<br>
                                 |   NAT44 Session delete   |      2 |<br>
                                 | NAT Addresses exhausted  |      3 |<br>
                                 |   NAT64 Session create   |      4 |<br>
                                 |   NAT64 Session delete   |      5 |<br>
                                 |     NAT44 BIB create     |      6 |<br>
                                 |     NAT44 BIB delete     |      7 |<br>
                                 |     NAT64 BIB create     |      8 |<br>
                                 |     NAT64 BIB delete     |      9 |<br>
                                 |   NAT ports exhausted    |     10 |<br>
                                 |      Quota exceeded      |     11 |<br>
                                 |  Address binding create  |     12 |<br>
                                 |  Address binding delete  |     13 |<br>
                                 |  Port block allocation   |     14 |<br>
                                 | Port block de-allocation |     15 |<br>
                                 |    Threshold reached     |     16 |<br>
                                 +--------------------------+--------+<br>
              <br>
                                      Table 2: NAT Event ID table<br>
              <br>
              5.4.  Quota exceeded Event types<br>
              <br>
                 The following table shows the sub event types for the
              Quota exceeded<br>
                 or limits reached event.  The events that can be
              reported are the<br>
                 Maximum session entries limit reached, Maximum BIB
              entries limit<br>
                 reached, Maximum session/BIB entries per user limit
              reached and<br>
                 maximum subscribers or hosts limit reached.<br>
              <br>
                         
              +---------------------------------------+--------+<br>
                          |       Quota Exceeded Event Name       |
              Values |<br>
                         
              +---------------------------------------+--------+<br>
                          |        Maximum Session entries        |     
              1 |<br>
                          |          Maximum BIB entries          |     
              2 |<br>
                          |        Maximum entries per user       |     
              3 |<br>
                          |  Maximum active hosts or subscribers  |     
              4 |<br>
                          |  Maximum fragments pending reassembly |     
              5 |<br>
                         
              +---------------------------------------+--------+<br>
              <br>
                                  Table 3: Quota Exceeded event table<br>
              <br>
              5.5.  Threshold reached Event types<br>
              <br>
                 The following table shows the sub event types for the
              threshold<br>
                 reached event.  The administrator can configure the
              thresholds and<br>
                 whenever the threshold is reached or exceeded, the
              corresponding<br>
                 events are generated.<br>
              <br>
                 The address pool high threshold event will be reported
              when the<br>
                 address pool reaches a high water mark as defined by
              the operator.<br>
                 This will sever as an indication that the operator
              might have to add<br>
                 more addresses to the pool or an indication that the
              subsequent users<br>
                 may be denied NAT translation mappings.<br>
              <br>
                 The address and port mapping high threshold event is
              generated, when<br>
                 the number of ports in the configured address pool has
              reached a<br>
                 configured threshold.<br>
              <br>
                 The per-user address and port mapping high threshold is
              generated<br>
                 when a single user uses more address and port mapping
              than a<br>
                 configured threshold.<br>
              <br>
                
              +---------------------------------------------------------+--------+<br>
                 |              Threshold Exceeded Event
              Name              | Values |<br>
                
              +---------------------------------------------------------+--------+<br>
                 |            Address pool high threshold
              event            |      1 |<br>
                 |             Address pool low threshold
              event            |      2 |<br>
                 |      Address and port mapping high threshold
              event      |      3 |<br>
                 |  Address and port mapping per user high threshold
              event |      4 |<br>
                 |       Global Address mapping high threshold
              event       |      5 |<br>
                
              +---------------------------------------------------------+--------+<br>
              <br>
                                    Table 4: Threshold event table<br>
              <br>
              5.6.  Templates for NAT Events<br>
              <br>
                 The following is the template of events that will have
              to logged.<br>
                                                             
              ^^^^^^^^^^^^^^^^^^^<br>
              <br>
              SD: I think this is a nit, but the sentence is garbled.
              "will be logged"?<br>
              <br>
                 The events below are identified at the time of this
              writing but the<br>
                 events are expandable.  Depending on the implementation
              and<br>
                 ^^^^^^^^^^^^^^^^^^^^^<br>
              SD: this is a nit, but "set of events is extensible", I
              think.</font></div>
        </div>
      </span>
      <div><br>
      </div>
      <div>[Senthil] Agree. (to both comments).</div>
    </blockquote>
    <br>
    Thanks,<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <span id="OLK_SRC_BODY_SECTION">
        <div>
          <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
              New,Courier,monospace">   configuration various IE's
              specified can be included or ignored.<br>
              <br>
              5.6.1.  NAT44 create and delete session events<br>
              <br>
                 These events will be generated when a NAT44 session is
              created or<br>
                 deleted.  The template will be the same, the natEvent
              will indicate<br>
                 whether it is a create or a delete event.  The
              following is a<br>
                 template of the event.<br>
              <br>
                 The destination address and port information is
              optional as required<br>
                 by [RFC6888].  However, when the destination
              information is<br>
                 suppressed, the session log event contains the same
              information as<br>
                 the BIB event.  In such cases, the NAT device SHOULD
              NOT send both<br>
                 BIB and session events.<br>
              <br>
                   
              +----------------------------------+-------------+-----------+<br>
                    |            Field Name            | Size (bits) |
              Mandatory |<br>
                   
              +----------------------------------+-------------+-----------+<br>
                    |            timeStamp             |          64
              |    Yes    |<br>
                    |          natInstanceID           |          32
              |     No    |<br>
                    |       vlanID/ingressVRFID        |          32
              |     No    |<br>
                    |        sourceIPv4Address         |          32
              |    Yes    |<br>
                    |     postNATSourceIPv4Address     |          32
              |    Yes    |<br>
                    |        protocolIdentifier        |           8
              |    Yes    |<br>
                    |       sourceTransportPort        |          16
              |    Yes    |<br>
                    |   postNAPTsourceTransportPort    |          16
              |    Yes    |<br>
                    |      destinationIPv4Address      |          32
              |     No    |<br>
                    |  postNATDestinationIPv4Address   |          32
              |     No    |<br>
                    |     destinationTransportPort     |          16
              |     No    |<br>
                    | postNAPTdestinationTransportPort |          16
              |     No    |<br>
                    |       internalAddressRealm       |           8
              |     No    |<br>
                    |       externalAddressRealm       |           8
              |     No    |<br>
                    |             natEvent             |           8
              |    Yes    |<br>
                   
              +----------------------------------+-------------+-----------+<br>
              <br>
                             Table 5: NAT44 Session delete/create
              template<br>
              <br>
              5.6.2.  NAT64 create and delete session events<br>
              <br>
                 These events will be generated when a NAT64 session is
              created or<br>
                 deleted.  The following is a template of the event.<br>
              <br>
                   
              +----------------------------------+-------------+-----------+<br>
                    |            Field Name            | Size (bits) |
              Mandatory |<br>
                   
              +----------------------------------+-------------+-----------+<br>
                    |            timeStamp             |          64
              |    Yes    |<br>
                    |          natInstanceID           |          32
              |     No    |<br>
                    |       vlanID/ingressVRFID        |          32
              |     No    |<br>
                    |        sourceIPv6Address         |         128
              |    Yes    |<br>
                    |     postNATSourceIPv4Address     |          32
              |    Yes    |<br>
                    |        protocolIdentifier        |           8
              |    Yes    |<br>
                    |       sourceTransportPort        |          16
              |    Yes    |<br>
                    |   postNAPTsourceTransportPort    |          16
              |    Yes    |<br>
                    |      destinationIPv6Address      |         128
              |     No    |<br>
                    |  postNATDestinationIPv4Address   |          32
              |     No    |<br>
                    |     destinationTransportPort     |          16
              |     No    |<br>
                    | postNAPTdestinationTransportPort |          16
              |     No    |<br>
                    |       internalAddressRealm       |           8
              |     No    |<br>
                    |       externalAddressRealm       |           8
              |     No    |<br>
                    |             natEvent             |           8
              |    Yes    |<br>
                   
              +----------------------------------+-------------+-----------+<br>
              <br>
                          Table 6: NAT64 session create/delete event
              template<br>
              <br>
              5.6.3.  NAT44 BIB create and delete events<br>
              <br>
                 These events will be generated when a NAT44 Bind entry
              is created or<br>
                 deleted.  The following is a template of the event.<br>
              <br>
                      
              +-----------------------------+-------------+-----------+<br>
                       |          Field Name         | Size (bits) |
              Mandatory |<br>
                      
              +-----------------------------+-------------+-----------+<br>
                       |          timeStamp          |          64 |   
              Yes    |<br>
                       |        natInstanceID        |          32 |    
              No    |<br>
                       |     vlanID/ingressVRFID     |          32 |    
              No    |<br>
                       |      sourceIPv4Address      |          32 |   
              Yes    |<br>
                       |   postNATSourceIPv4Address  |          32 |   
              Yes    |<br>
                       |      protocolIdentifier     |           8 |    
              No    |<br>
                       |     sourceTransportPort     |          16 |    
              No    |<br>
                       | postNAPTsourceTransportPort |          16 |    
              No    |<br>
                       |     internalAddressRealm    |           8 |    
              No    |<br>
                       |     externalAddressRealm    |           8 |    
              No    |<br>
                       |           natEvent          |           8 |   
              Yes    |<br>
                      
              +-----------------------------+-------------+-----------+<br>
              <br>
                            Table 7: NAT44 BIB create/delete event
              template<br>
              <br>
              5.6.4.  NAT64 BIB create and delete events<br>
              <br>
                 These events will be generated when a NAT64 Bind entry
              is created or<br>
                 deleted.  The following is a template of the event.<br>
              <br>
                      
              +-----------------------------+-------------+-----------+<br>
                       |          Field Name         | Size (bits) |
              Mandatory |<br>
                      
              +-----------------------------+-------------+-----------+<br>
                       |          timeStamp          |          64 |   
              Yes    |<br>
                       |        natInstanceID        |          32 |    
              No    |<br>
                       |     vlanID/ingressVRFID     |          32 |    
              No    |<br>
                       |      sourceIPv6Address      |         128 |   
              Yes    |<br>
                       |   postNATSourceIPv4Address  |          32 |   
              Yes    |<br>
                       |      protocolIdentifier     |           8 |    
              No    |<br>
                       |     sourceTransportPort     |          16 |    
              No    |<br>
                       | postNAPTsourceTransportPort |          16 |    
              No    |<br>
                       |     internalAddressRealm    |           8 |    
              No    |<br>
                       |     externalAddressRealm    |           8 |    
              No    |<br>
                       |           natEvent          |           8 |   
              Yes    |<br>
                      
              +-----------------------------+-------------+-----------+<br>
              <br>
                            Table 8: NAT64 BIB create/delete event
              template<br>
              <br>
              5.6.5.  Addresses Exhausted event<br>
              <br>
                 This event will be generated when a NAT device runs out
              of global<br>
                 IPv4 addresses in a given pool of addresses. 
              Typically, this event<br>
                 would mean that the NAT device wont be able to create
              any new<br>
                                                ^^^^<br>
              SD: "won't"</font></div>
        </div>
      </span>
      <div><br>
      </div>
      <div bgcolor="#FFFFFF" text="#000000">[Senthil] Ok.<font
          face="Courier New,Courier,monospace"><br>
        </font></div>
    </blockquote>
    <br>
    Thanks,<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
          New,Courier,monospace">
          <br>
             translations until some addresses/ports are freed.  This
          event SHOULD<br>
             be rate limited as many packets hitting the device at the
          same time<br>
             will trigger a burst of addresses exhausted events.<br>
          <br>
             The following is a template of the event.  Note that either
          the NAT<br>
             pool name or the nat pool identifier should be logged, but
          not both.<br>
          <br>
          SD: I lack understanding, but I didn't see anything that
          looked like a NAT pool name in the template. Did I miss
          something?</font></div>
      <span id="OLK_SRC_BODY_SECTION">
        <div>
        </div>
      </span>
      <div><br>
      </div>
      <div>[Senthil] We decided not to use a string like a pool name
        instead use a poolID, which is a unique identifier for each pool
        name. The reason being that the logs could become fairly large </div>
      <div>If we have to carry the names and some of the NAT engines
        implement this in the hardware that lacks the string processing
        capability.</div>
    </blockquote>
    <br>
    OK, that helps. I'm understanding that a different template might
    have included a pool name, but not a poolID, is that right?<br>
    <br>
    I'm somewhat uneasy about the "either should be logged, but not
    both" text.<br>
    <br>
    Same question as usual - is this an RFC 2119 SHOULD that helps with
    interoperation, or is this about an implementation choice?<br>
    <br>
    If it's an RFC 2119 SHOULD, robust collectors will need to do
    something if a log arrives with both a pool name and a poolID. If
    it's a MUST, a collector wouldn't accept the log (however the
    collector would decide to do that).<br>
    <br>
    If it's not an RFC 2119 SHOULD, but just implementation guidance,
    the explanation you provided would be more helpful (something like
    "could include a pool name, but some NAT engines are implemented in
    hardware that lacks string processing capability, and these are
    permitted to substitute a poolID. There's no reason to provide both
    a pool name and a poolID").<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <span id="OLK_SRC_BODY_SECTION">
        <div>
          <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
              New,Courier,monospace">               
              +---------------+-------------+-----------+<br>
                              |   Field Name  | Size (bits) | Mandatory
              |<br>
                             
              +---------------+-------------+-----------+<br>
                              |   timeStamp   |          64 |    Yes   
              |<br>
                              | natInstanceID |          32 |     No   
              |<br>
                              |    natEvent   |           8 |    Yes   
              |<br>
                              |   natPoolID   |          32 |    Yes   
              |<br>
                             
              +---------------+-------------+-----------+<br>
              <br>
                               Table 9: Address Exhausted event template<br>
              <br>
              5.6.6.  Ports Exhausted event<br>
              <br>
                 This event will be generated when a NAT device runs out
              of ports for<br>
                 a global IPv4 address.  Port exhaustion shall be
              reported per<br>
                 protocol (UDP, TCP etc).  This event SHOULD be rate
              limited as many<br>
                 packets hitting the device at the same time will
              trigger a burst of<br>
                 port exhausted events.<br>
              <br>
                 The following is a template of the event.<br>
              <br>
                       
              +--------------------------+-------------+-----------+<br>
                        |        Field Name        | Size (bits) |
              Mandatory |<br>
                       
              +--------------------------+-------------+-----------+<br>
                        |        timeStamp         |          64 |   
              Yes    |<br>
                        |      natInstanceID       |          32 |    
              No    |<br>
                        |         natEvent         |           8 |   
              Yes    |<br>
                        | postNATSourceIPv4Address |          32 |   
              Yes    |<br>
                        |    protocolIdentifier    |           8 |   
              Yes    |<br>
                       
              +--------------------------+-------------+-----------+<br>
              <br>
                               Table 10: Ports Exhausted event template<br>
              <br>
              5.6.7.  Quota exceeded events<br>
              <br>
                 This event will be generated when a NAT device cannot
              allocate<br>
                 resources as a result of an administratively defined
              policy.  The<br>
                 quota exceeded event templates are described below<br>
                                                                   ^<br>
              SD: missing period</font></div>
        </div>
      </span>
      <div>[Senthil] Ok.</div>
    </blockquote>
    <br>
    Thanks,<br>
    <br>
    <blockquote cite="mid:CF89605B.1009FB%25ssenthil@cisco.com"
      type="cite">
      <span id="OLK_SRC_BODY_SECTION">
        <div>
          <div bgcolor="#FFFFFF" text="#000000"><font face="Courier
              New,Courier,monospace">5.6.7.1.  Maximum session entries
              exceeded<br>
              <br>
                 The maximum session entries exceeded is generated when
              the<br>
                 administratively configured limit is reached.  The
              following is the<br>
                 template of the event.<br>
              <br>
                            
              +-----------------+-------------+-----------+<br>
                             |    Field Name   | Size (bits) | Mandatory
              |<br>
                            
              +-----------------+-------------+-----------+<br>
                             |    timeStamp    |          64 |    Yes   
              |<br>
                             |  natInstanceID  |          32 |     No   
              |<br>
                             |     natEvent    |           8 |    Yes   
              |<br>
                             |  natLimitEvent  |          32 |    Yes   
              |<br>
                             | configuredLimit |          32 |    Yes   
              |<br>
                            
              +-----------------+-------------+-----------+<br>
              <br>
                           Table 11: Session Entries Exceeded event
              template<br>
              <br>
              5.6.7.2.  Maximum BIB entries exceeded<br>
              <br>
                 The maximum BIB entries exceeded is generated when the<br>
                 administratively configured limit is reached.  The
              following is the<br>
                 template of the event.<br>
              <br>
                            
              +-----------------+-------------+-----------+<br>
                             |    Field Name   | Size (bits) | Mandatory
              |<br>
                            
              +-----------------+-------------+-----------+<br>
                             |    timeStamp    |          64 |    Yes   
              |<br>
                             |  natInstanceID  |          32 |     No   
              |<br>
                             |     natEvent    |           8 |    Yes   
              |<br>
                             |  natLimitEvent  |          32 |    Yes   
              |<br>
                             | configuredLimit |          32 |    Yes   
              |<br>
                            
              +-----------------+-------------+-----------+<br>
              <br>
                             Table 12: BIB Entries Exceeded event
              template<br>
              <br>
              5.6.7.3.  Maximum entries per user exceeded<br>
              <br>
                 This event is generated when a single user reaches the<br>
                 administratively configured limit.  The following is
              the template of<br>
                 the event.<br>
              <br>
                        
              +---------------------+-------------+---------------+<br>
                         |      Field Name     | Size (bits) |  
              Mandatory   |<br>
                        
              +---------------------+-------------+---------------+<br>
                         |      timeStamp      |          64 |     
              Yes      |<br>
                         |    natInstanceID    |          32 |      
              No      |<br>
                         |       natEvent      |           8 |     
              Yes      |<br>
                         |    natLimitEvent    |          32 |     
              Yes      |<br>
                         |   configuredLimit   |          32 |     
              Yes      |<br>
                         | vlanID/ingressVRFID |          32 |      
              No      |<br>
                         |  sourceIPv4 address |          32 | Yes for
              NAT44 |<br>
                         |  sourceIPv6 address |         128 | Yes for
              NAT64 |<br>
                        
              +---------------------+-------------+---------------+<br>
              <br>
                          Table 13: Per-user Entries Exceeded event
              template<br>
              <br>
              5.6.7.4.  Maximum active host or subscribers exceeded<br>
              <br>
                 This event is generated when the number of allowed
              hosts or<br>
                 subscribers reaches the administratively configured
              limit.  The<br>
                 following is the template of the event.<br>
              <br>
                            
              +-----------------+-------------+-----------+<br>
                             |    Field Name   | Size (bits) | Mandatory
              |<br>
                            
              +-----------------+-------------+-----------+<br>
                             |    timeStamp    |          64 |    Yes   
              |<br>
                             |  natInstanceID  |          32 |     No   
              |<br>
                             |     natEvent    |           8 |    Yes   
              |<br>
                             |  natLimitEvent  |          32 |    Yes   
              |<br>
                             | configuredLimit |          32 |    Yes   
              |<br>
                            
              +-----------------+-------------+-----------+<br>
              <br>
                      Table 14: Maximum hosts/subscribers Exceeded event
              template<br>
              <br>
              5.6.7.5.  Maximum fragments pending reassembly exceeded<br>
              <br>
                 This event is generated when the number of fragments
              pending<br>
                 reassembly reaches the administratively configured
              limit.  The<br>
                 following is the template of the event.<br>
              <br>
                       
              +----------------------+-------------+---------------+<br>
                        |      Field Name      | Size (bits) |  
              Mandatory   |<br>
                       
              +----------------------+-------------+---------------+<br>
                        |      timeStamp       |          64 |     
              Yes      |<br>
                        |    natInstanceID     |          32 |      
              No      |<br>
                        |       natEvent       |           8 |     
              Yes      |<br>
                        |    natLimitEvent     |          32 |     
              Yes      |<br>
                        |   configuredLimit    |          32 |     
              Yes      |<br>
                        | internalAddressRealm |           8 |     
              Yes      |<br>
                        | vlanID/ingressVRFID  |          32 |      
              No      |<br>
                        |  sourceIPv4 address  |          32 | Yes for
              NAT44 |<br>
                        |  sourceIPv6 address  |         128 | Yes for
              NAT64 |<br>
                       
              +----------------------+-------------+---------------+<br>
              <br>
                     Table 15: Maximum fragments pending reassembly
              Exceeded event<br>
                                               template<br>
              <br>
              5.6.8.  Threshold reached events<br>
              <br>
                 This event will be generated when a NAT device reaches
              a operator<br>
                 configured threshold when allocating resources.  The
              threshold<br>
                 reached events are described in the section above.  The
              following is<br>
                 a template of the individual events.<br>
              <br>
              5.6.8.1.  Address pool high or low threshold reached<br>
              <br>
                 This event is generated when the high or low threshold
              is reached for<br>
                 the address pool.  The template is the same for both
              high and low<br>
                 threshold events<br>
              <br>
                           
              +-------------------+-------------+-----------+<br>
                            |     Field Name    | Size (bits) |
              Mandatory |<br>
                           
              +-------------------+-------------+-----------+<br>
                            |     timeStamp     |          64 |   
              Yes    |<br>
                            |   natInstanceID   |          32 |    
              No    |<br>
                            |      natEvent     |           8 |   
              Yes    |<br>
                            | natThresholdEvent |          32 |   
              Yes    |<br>
                            |     natPoolID     |          32 |   
              Yes    |<br>
                            |  configuredLimit  |          32 |   
              Yes    |<br>
                           
              +-------------------+-------------+-----------+<br>
              <br>
                   Table 16: Address pool high/low threshold reached
              event template<br>
              <br>
              5.6.8.2.  Address and port high threshold reached<br>
              <br>
                 This event is generated when the high threshold is
              reached for the<br>
                 address pool and ports.<br>
              <br>
                           
              +-------------------+-------------+-----------+<br>
                            |     Field Name    | Size (bits) |
              Mandatory |<br>
                           
              +-------------------+-------------+-----------+<br>
                            |     timeStamp     |          64 |   
              Yes    |<br>
                            |   natInstanceID   |          32 |    
              No    |<br>
                            |      natEvent     |           8 |   
              Yes    |<br>
                            | natThresholdEvent |          32 |   
              Yes    |<br>
                            |  configuredLimit  |          32 |   
              Yes    |<br>
                           
              +-------------------+-------------+-----------+<br>
              <br>
                     Table 17: Address port high threshold reached event
              template<br>
              <br>
              5.6.8.3.  Per-user Address and port high threshold reached<br>
              <br>
                 This event is generated when the high threshold is
              reached for the<br>
                 per-user address pool and ports.<br>
              <br>
                        
              +---------------------+-------------+---------------+<br>
                         |      Field Name     | Size (bits) |  
              Mandatory   |<br>
                        
              +---------------------+-------------+---------------+<br>
                         |      timeStamp      |          64 |     
              Yes      |<br>
                         |    natInstanceID    |          32 |      
              No      |<br>
                         |       natEvent      |           8 |     
              Yes      |<br>
                         |  natThresholdEvent  |          32 |     
              Yes      |<br>
                         |   configuredLimit   |          32 |     
              Yes      |<br>
                         | vlanID/ingressVRFID |          32 |      
              No      |<br>
                         |  sourceIPv4 address |          32 | Yes for
              NAT44 |<br>
                         |  sourceIPv6 address |         128 | Yes for
              NAT64 |<br>
                        
              +---------------------+-------------+---------------+<br>
              <br>
                 Table 18: Per-user Address port high threshold reached
              event template<br>
              <br>
              5.6.8.4.  Global Address mapping high threshold reached<br>
              <br>
                 This event is generated when the high is reached for
              the per-user<br>
                 address pool and ports.  This is generated only by NAT
              devices that<br>
                 use a address pooling behavior of paired.<br>
              <br>
                          
              +---------------------+-------------+-----------+<br>
                           |      Field Name     | Size (bits) |
              Mandatory |<br>
                          
              +---------------------+-------------+-----------+<br>
                           |      timeStamp      |          64 |   
              Yes    |<br>
                           |    natInstanceID    |          32 |    
              No    |<br>
                           |       natEvent      |           8 |   
              Yes    |<br>
                           |  natThresholdEvent  |          32 |   
              Yes    |<br>
                           |   configuredLimit   |          32 |   
              Yes    |<br>
                           | vlanID/ingressVRFID |          32 |    
              No    |<br>
                          
              +---------------------+-------------+-----------+<br>
              <br>
                     Table 19: Global Address mapping high threshold
              reached event<br>
                                               template<br>
              <br>
              5.6.9.  Address binding create and delete events<br>
              <br>
                 These events will be generated when a NAT device binds
              a local<br>
                 address with a global address and when the global
              address is freed.<br>
                 This binding event happens when the first packet of the
              first flow<br>
                 from a host in the private realm.<br>
              <br>
                  
              +--------------------------------+-------------+---------------+<br>
                   |           Field Name           | Size (bits) |  
              Mandatory   |<br>
                  
              +--------------------------------+-------------+---------------+<br>
                   |           timeStamp            |          64 |     
              Yes      |<br>
                   |         natInstanceID          |          32
              |       No      |<br>
                   |            natEvent            |           8 |     
              Yes      |<br>
                   |       sourceIPv4 address       |          32 | Yes
              for NAT44 |<br>
                   |       sourceIPv6 address       |         128 | Yes
              for NAT64 |<br>
                   | Translated Source IPv4 Address |          32 |     
              Yes      |<br>
                  
              +--------------------------------+-------------+---------------+<br>
              <br>
                                Table 20: NAT Address Binding template<br>
              <br>
              5.6.10.  Port block allocation and de-allocation<br>
              <br>
                 This event will be generated when a NAT device
              allocates/de-allocates<br>
                 ports in a bulk fashion, as opposed to allocating a
              port on a per<br>
                 flow basis.<br>
              <br>
                 portRangeStart represents the starting value of the
              range.<br>
              <br>
                 portRangeEnd represents the ending value of the range.<br>
              <br>
                 NAT devices would do this in order to reduce logs and
              potentially to<br>
                 limit the number of connections a subscriber is allowed
              to use.  In<br>
                 the following Port Block allocation template, the
              portRangeStart and<br>
                 portRangeEnd must be specified.<br>
              <br>
              <br>
              Sivakumar &amp; Penno        Expires August 15,
              2014               [Page 17]<br>
              <br>
              Internet-Draft          IPFIX IEs for NAT logging         
              February 2014<br>
              <br>
                 It is up to the implementation to choose to consolidate
              log records<br>
                 in case two consecutive port ranges for the same user
              are allocated<br>
                 or freed.<br>
              <br>
                  
              +--------------------------------+-------------+---------------+<br>
                   |           Field Name           | Size (bits) |  
              Mandatory   |<br>
                  
              +--------------------------------+-------------+---------------+<br>
                   |           timeStamp            |          64 |     
              Yes      |<br>
                   |         natInstanceID          |          32
              |       No      |<br>
                   |            natEvent            |           8 |     
              Yes      |<br>
                   |       sourceIPv4 address       |          32 | Yes
              for NAT44 |<br>
                   |       sourceIPv6 address       |         128 | Yes
              for NAT64 |<br>
                   | Translated Source IPv4 Address |          32 |     
              Yes      |<br>
                   |         portRangeStart         |          16 |     
              Yes      |<br>
                   |          portRangeEnd          |          16
              |       No      |<br>
                  
              +--------------------------------+-------------+---------------+<br>
              <br>
                          Table 21: NAT Port Block Allocation event
              template<br>
              <br>
              6.  Encoding<br>
              <br>
              6.1.  IPFIX<br>
              <br>
                 This document uses IPFIX as the encoding mechanism to
              describe the<br>
                 logging of NAT events.  However, the information that
              should be<br>
                 logged SHOULD be the same irrespective of what kind of
              encoding<br>
                 scheme is used.  IPFIX is chosen because is it an IETF
              standard that<br>
                 meets all the needs for a reliable logging mechanism. 
              IPFIX provides<br>
                 the flexibility to the logging device to define the
              data sets that it<br>
                 is logging.  The IEs specified for logging MUST be the
              same<br>
                 irrespective of the encoding mechanism used.<br>
              <br>
              7.  Acknowledgements<br>
              <br>
                 Thanks to Dan Wing, Selvi Shanmugam, Mohamed Boucadir,
              Jacni Qin<br>
                 Ramji Vaithianathan, Simon Perreault, Jean-Francois
              Tremblay, Paul<br>
                 Aitken and Julia Renouard for their review and
              comments.<br>
              <br>
              8.  IANA Considerations<br>
              <br>
                 The following information elements are requested from
              IANA IPFIX<br>
                 registry.<br>
              <br>
                 natInstanceId<br>
              <br>
                 externalAddressRealm<br>
              <br>
                 natLimitEvent<br>
              <br>
              9.  Management Considerations<br>
              <br>
                 This section considers requirements for management of
              the log system<br>
                 to support logging of the events described above.  It
              first covers<br>
                 requirements applicable to log management in general. 
              Any additional<br>
                 standardization required to fullfil these requirements
              is out of<br>
                 scope of the present document.  Some management
              considerations is<br>
                 covered in [I-D.behave-syslog-nat-logging].  This
              document covers the<br>
                 additional considerations.<br>
              <br>
              9.1.  Ability to collect events from multiple NAT devices<br>
              <br>
                 An IPFIX collector should be able to collect events
              from multiple NAT<br>
                 devices and be able to decipher events based on the
              sourceID in the<br>
                 IPFIX header.<br>
              <br>
              9.2.  Ability to suppress events<br>
              <br>
                 The exhaustion events can be overwhelming during
              traffic bursts and<br>
                 hence should be handled by the NAT devices to rate
              limit them before<br>
                 sending them to the collectors.  For eg. when the port
              exhaustion<br>
                 happens during bursty conditions, instead of sending a
              port<br>
                 exhaustion event for every packet, the exhaustion
              events should be<br>
                 rate limited by the NAT device.<br>
              <br>
              10.  Security Considerations<br>
              <br>
                 None.<br>
              <br>
              11.  References<br>
              <br>
              11.1.  Normative References<br>
              <br>
                 [RFC2119]  Bradner, S., "Key words for use in RFCs to
              Indicate<br>
                            Requirement Levels", BCP 14, RFC 2119, March
              1997.<br>
              <br>
                 [RFC2663]  Srisuresh, P. and M. Holdrege, "IP Network
              Address<br>
                            Translator (NAT) Terminology and
              Considerations", RFC<br>
                            2663, August 1999.<br>
              <br>
                 [RFC4787]  Audet, F. and C. Jennings, "Network Address
              Translation<br>
                            (NAT) Behavioral Requirements for Unicast
              UDP", BCP 127,<br>
                            RFC 4787, January 2007.<br>
              <br>
                 [RFC5382]  Guha, S., Biswas, K., Ford, B., Sivakumar,
              S., and P.<br>
                            Srisuresh, "NAT Behavioral Requirements for
              TCP", BCP 142,<br>
                            RFC 5382, October 2008.<br>
              <br>
                 [RFC6146]  Bagnulo, M., Matthews, P., and I. van
              Beijnum, "Stateful<br>
                            NAT64: Network Address and Protocol
              Translation from IPv6<br>
                            Clients to IPv4 Servers", RFC 6146, April
              2011.<br>
              <br>
                 [RFC6302]  Durand, A., Gashinsky, I., Lee, D., and S.
              Sheppard,<br>
                            "Logging Recommendations for Internet-Facing
              Servers", BCP<br>
                            162, RFC 6302, June 2011.<br>
              <br>
                 [RFC6888]  Perreault, S., Yamagata, I., Miyakawa, S.,
              Nakagawa, A.,<br>
                            and H. Ashida, "Common Requirements for
              Carrier-Grade NATs<br>
                            (CGNs)", BCP 127, RFC 6888, April 2013.<br>
              <br>
              11.2.  Informative References<br>
              <br>
                 [I-D.ietf-behave-syslog-nat-logging]<br>
                            Chen, Z., Zhou, C., Tsou, T., and T. Taylor,
              "Syslog<br>
                            Format for NAT Logging",
              draft-ietf-behave-syslog-nat-<br>
                            logging-06 (work in progress), January 2014.<br>
              <br>
                 [IPFIX-IANA]<br>
                            IANA, "IPFIX Information Elements registry",<br>
                            <a moz-do-not-send="true"
                class="moz-txt-link-rfc2396E"
                href="http://www.iana.org/assignments/ipfix">
                &lt;http://www.iana.org/assignments/ipfix&gt;</a>.<br>
              <br>
                 [RFC5101bis]<br>
                            Claise, B. and B. Trammel, "Specification of
              the IP Flow<br>
                            Information eXport (IPFIX) Protocol for the
              Exchange of<br>
                            Flow Information", July 2013.<br>
              <br>
                 [RFC5102bis]<br>
                            Claise, B. and B. Trammel, "Information
              Model for IP Flow<br>
                            Information eXport (IPFIX)", February 2013.<br>
              <br>
                 [RFC5470]  Sadasivan, G., Brownlee, N., Claise, B., and
              J. Quittek,<br>
                            "Architecture for IP Flow Information
              Export", RFC 5470,<br>
                            March 2009.<br>
              <br>
              Authors' Addresses<br>
              <br>
                 Senthil Sivakumar<br>
                 Cisco Systems<br>
                 7100-8 Kit Creek Road<br>
                 Research Triangle Park, North Carolina  27709<br>
                 USA<br>
              <br>
                 Phone: +1 919 392 5158<br>
              <br>
                 Renaldo Penno<br>
                 Cisco Systems<br>
                 170 W Tasman Drive<br>
                 San Jose, California  95035<br>
                 USA<br>
              <br>
                 Email: <a moz-do-not-send="true"
                class="moz-txt-link-abbreviated"
                href="mailto:repenno@cisco.com">repenno@cisco.com</a><br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              <br>
              Sivakumar &amp; Penno        Expires August 15,
              2014               [Page 21]</font></div>
        </div>
      </span>
    </blockquote>
    <br>
  </body>
</html>

--------------030908080302000709080908--


From nobody Wed May 28 08:13:54 2014
Return-Path: <ssenthil@cisco.com>
X-Original-To: behave@ietfa.amsl.com
Delivered-To: behave@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 786CE1A01F6 for <behave@ietfa.amsl.com>; Tue, 27 May 2014 11:30:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -11.47
X-Spam-Level: 
X-Spam-Status: No, score=-11.47 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_FONT_FACE_BAD=0.981, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xIjlYB556vws for <behave@ietfa.amsl.com>; Tue, 27 May 2014 11:30:07 -0700 (PDT)
Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C32DB1A0650 for <behave@ietf.org>; Tue, 27 May 2014 11:30:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=192283; q=dns/txt; s=iport; t=1401215403; x=1402425003; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=jUmsQD4s+yk9IgI1TGqVirac2ztDied6up3uPH+7nJY=; b=klWixpOeJ5KqG6gQD5D68gGaObwKCkdZXQyQCTpNq9ouErhRHhB/cgG2 8utvU0p1qpO/EcUg6lDGR6MJzcJyqR+PCS94VZncs4YqwaiyYKvFTa1F9 C+EkL0zRz2qcHwF4KCGLqwgV3y9MEQ+pkfJAMuA6IdcaIgHXN/jCc+lQD E=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AgALADbZhFOtJA2M/2dsb2JhbABPBwOCQkVSWLY8DIFaiXoBgQ4WdIIlAQEBBBoBTAcEBw4CAgEIEQECAQIhAQYHGwYRFAMGCAIEAQ0FCYglAxENz1YNhU8XBIwoEIEyAgEFBAEGAQMEHRsBEAcRhC8EjDuJN4ILgXaNNYVygzhsgQEBCBci
X-IronPort-AV: E=Sophos;i="4.98,921,1392163200";  d="scan'208,217";a="328294385"
Received: from alln-core-7.cisco.com ([173.36.13.140]) by rcdn-iport-6.cisco.com with ESMTP; 27 May 2014 18:30:00 +0000
Received: from xhc-rcd-x08.cisco.com (xhc-rcd-x08.cisco.com [173.37.183.82]) by alln-core-7.cisco.com (8.14.5/8.14.5) with ESMTP id s4RIU0B4023788 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Tue, 27 May 2014 18:30:00 GMT
Received: from xmb-rcd-x15.cisco.com ([169.254.5.188]) by xhc-rcd-x08.cisco.com ([173.37.183.82]) with mapi id 14.03.0123.003; Tue, 27 May 2014 13:29:59 -0500
From: "Senthil Sivakumar (ssenthil)" <ssenthil@cisco.com>
To: Spencer Dawkins <spencerdawkins.ietf@gmail.com>, "draft-ietf-behave-ipfix-nat-logging@tools.ietf.org" <draft-ietf-behave-ipfix-nat-logging@tools.ietf.org>
Thread-Topic: AD Evaluation of draft-ietf-behave-ipfix-nat-logging-03
Thread-Index: AQHPZXuW1xHWpTEStEWEs33L9nVI5ZstvOcAgCFhhwCABdqugA==
Date: Tue, 27 May 2014 18:29:57 +0000
Message-ID: <CFAA34BB.106C60%ssenthil@cisco.com>
References: <5362ADCB.4050802@gmail.com> <CF89605B.1009FB%ssenthil@cisco.com> <537FB834.3010705@gmail.com>
In-Reply-To: <537FB834.3010705@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.4.1.140326
x-originating-ip: [64.102.83.140]
Content-Type: multipart/alternative; boundary="_000_CFAA34BB106C60ssenthilciscocom_"
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/behave/vJ3RggyCG4mADcUov1PCgM0JEwk
X-Mailman-Approved-At: Wed, 28 May 2014 08:13:53 -0700
Cc: "behave@ietf.org" <behave@ietf.org>
Subject: Re: [BEHAVE] AD Evaluation of draft-ietf-behave-ipfix-nat-logging-03
X-BeenThere: behave@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: mailing list of BEHAVE IETF WG <behave.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/behave>, <mailto:behave-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/behave/>
List-Post: <mailto:behave@ietf.org>
List-Help: <mailto:behave-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 May 2014 18:30:17 -0000

--_000_CFAA34BB106C60ssenthilciscocom_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Hi Spencer,
Thanks for your comments again, please see inline [Senthil2].

From: Spencer Dawkins <spencerdawkins.ietf@gmail.com<mailto:spencerdawkins.=
ietf@gmail.com>>
Date: Friday, May 23, 2014 5:05 PM
To: Senthil Sivakumar <ssenthil@cisco.com<mailto:ssenthil@cisco.com>>, "dra=
ft-ietf-behave-ipfix-nat-logging@tools.ietf.org<mailto:draft-ietf-behave-ip=
fix-nat-logging@tools.ietf.org>" <draft-ietf-behave-ipfix-nat-logging@tools=
.ietf.org<mailto:draft-ietf-behave-ipfix-nat-logging@tools.ietf.org>>
Cc: "behave@ietf.org<mailto:behave@ietf.org>" <behave@ietf.org<mailto:behav=
e@ietf.org>>
Subject: Re: AD Evaluation of draft-ietf-behave-ipfix-nat-logging-03


On 05/02/2014 02:20 PM, Senthil Sivakumar (ssenthil) wrote:
Hi Spencer,
Thanks for the thorough review.
Please see inline for [Senthil]. If you agree, I will submit another versio=
n fixing all the issues raised and agreed upon. I will wait for your respon=
se.

Hi, Senthil,

Thanks for being responsive!

Just as a high-order bit, many of the questions I asked are whether the dra=
ft uses "required" to mean "this is the way it works" - there's a differenc=
e between "the sender transmits a log" and "the sender is required to trans=
mit a log". Does that make sense?

Ths draft says it uses requirements language as per RFC 2119, and RFC 2119 =
says

6. Guidance in the use of these Imperatives

   Imperatives of the type defined in this memo must be used with care
   and sparingly.  In particular, they MUST only be used where it is
   actually required for interoperation or to limit behavior which has
   potential for causing harm (e.g., limiting retransmisssions)  For
   example, they must not be used to try to impose a particular method
   on implementors where the method is not required for
   interoperability.

It's also worth mentioning that RFC 2119 is silent on case for requirements=
 language, your requirements terminology section only shows upper case exam=
ples, and most of the cases I'm asking about are in lower case, which makes=
 it less clear whether you intend "require" to be an RFC 2119 requirement w=
ord or not. This is a continuing source of controversy in the IETF, especia=
lly during cross-area review - my suggestion is that you either change the =
requirements language statement to include a statement about whether lower-=
case versions are intended as requirements language, or don't use the lower=
-case terms in the document.

I'll try to be clear in my detailed comments, but that's often what I'm try=
ing to get at.

[Senthil2] Ok, thanks.


Thanks
Senthil

From: Spencer Dawkins <spencerdawkins.ietf@gmail.com<mailto:spencerdawkins.=
ietf@gmail.com>>
Date: Thursday, May 1, 2014 4:25 PM
To: "draft-ietf-behave-ipfix-nat-logging@tools.ietf.org<mailto:draft-ietf-b=
ehave-ipfix-nat-logging@tools.ietf.org>" <draft-ietf-behave-ipfix-nat-loggi=
ng@tools.ietf.org<mailto:draft-ietf-behave-ipfix-nat-logging@tools.ietf.org=
>>
Cc: "behave@ietf.org<mailto:behave@ietf.org>" <behave@ietf.org<mailto:behav=
e@ietf.org>>
Subject: AD Evaluation of draft-ietf-behave-ipfix-nat-logging-03
Resent-From: <draft-alias-bounces@tools.ietf.org<mailto:draft-alias-bounces=
@tools.ietf.org>>
Resent-To: <repenno@cisco.com<mailto:repenno@cisco.com>>, Senthil Sivakumar=
 <ssenthil@cisco.com<mailto:ssenthil@cisco.com>>
Resent-Date: Thursday, May 1, 2014 4:26 PM

Dear draft-ietf-behave-ipfix-nat-logging Authors,

I've completed my AD evaluation for this draft. I found some things I'd lik=
e to see changed before proceeding, but most are editorial. Please take a l=
ook, and let me know what you think.

My notes follow ... you should be able to find my questions and comments by=
 searching for "SD:".

Thanks,

Spencer

In the Abstract

   NAT devices are required to log events like creation and deletion of
                   ^^^^^^^^
SD: Is this required, like, legally required, or ? Is it more like "Operato=
rs need NAT devices to log events ..."?
[Senthil] : It is the later, the network operators require the NAT devices =
to be able to log events.

We don't usually include requirements language in the Abstract (that happen=
s later, which is fine in the document body).

The longer I look at this, the more I think it's something like "Operators =
expect NAT devices to log events".

   translations and information about the resources it is managing.  The
   logs are required in many cases to identify an attacker or a host
   that was used to launch malicious attacks and/or for various other
   purposes of accounting.  Since there is no standard way of logging
   this information, different NAT devices behave differently and hence
                               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
SD: Is this "different NAT devices log this information differently"?
[Senthil] Correct, as the sentence says, "Since there is no standard way=85=
", each NAT device logs information in its own proprietary format.

I'm just trying to make sure the reader understands what you mean by "behav=
e differently" - NAT devices also behave differently when NATting.  I had t=
o guess at the meaning. Maybe everyone else will understand?

   it is difficult to expect a consistent behavior.  The lack of a
   consistent way makes it difficult to write the collector applications
   that would receive this data and process it to present useful
   information.  This document describes the information that is
   required to be logged by the NAT devices.
   ^^^^^^^^^^^^^^^^^^^^^^^^
SD: Same as previous question - is this "logged by"?

[Senthil] If a NAT device is logging events, these are the requirements tha=
t a NAT device should adhere to.

I know this seems tedious, but I'm not able to map what you provided as exp=
lanation onto the text you're explaining. What I'm seeing in the text is

A NAT MUST log this information

and what I'm seeing in your explanation is

IF a NAT is is logging information, here's how the NAT SHOULD log informati=
on.

I'm guessing that what you're saying is really "this document describes the=
 information that logging NAT devices produce".

This doesn't matter yet (you're still in the abstract, which shouldn't be p=
roviding requirements anyway), but in the body of the document, it needs to=
 be clear.
[Senthil2] : How about I revise the text as:

   Network operators expect NAT devices to log events like creation and del=
etion of
   translations and information about the resources it is managing.  The
   logs are essential in many cases to identify an attacker or a host
   that was used to launch malicious attacks and/or for various other
   purposes of accounting.  Since there is no standard way of logging
   this information, different NAT devices log the information using propri=
etary formats

   and hence it is difficult to expect a consistent behavior.  The lack of =
a
   consistent way to log the data makes it difficult to write the collector=
 applications
   that would receive this data and process it to present useful
   information.  This document describes the formats for logging of NAT eve=
nts.

2.  Introduction

   The IPFIX Protocol [RFC5101bis] defines a generic push mechanism for
   exporting information and events.  The IPFIX Information Model
   [IPFIX-IANA] defines a set of standard Information Elements (IEs)
   which can be carried by the IPFIX protocol.  This document details
   the IPFIX Information Elements(IEs) that are required for logging by
   a NAT device.  The document will specify the format of the IE's that
   are required to be logged by the NAT device and all the optional
       ^^^^^^^^^^^^^^^^^^^^^
SD: Now that we're in the document body, if this is required, shouldn't the=
re be a reference to where the requirements are stated?
[Senthil] This is the document that is specifying those requirements. Do yo=
u have any other suggestions of wording instead of "required by", would it =
be fine if I change the sentence from
"required to be logged" to "SHOULD be logged"?

Sorry, my first set of comments was bogus. What triggered my comments was t=
he use of lower-case terms from RFC 2119 (see my explanation above).

This could be "are REQUIRED" (the RFC 2119 requirements language you said y=
ou're using), or "are required" (if you change your paragraph about require=
ments language to say that case doesn't matter).

But "REQUIRED" is "MUST", so changing to "SHOULD" would be a change in your=
 intended meaning.

[Senthil2] I will change this to "are REQUIRED".



   This document and [I-D.behave-syslog-nat-logging] are provided in
   order to standardize the events and parameters to be recorded, using
   IPFIX [RFC5101bis] and SYSLOG [RFC5424]respectively.

I'm sorry I missed this question the first time. Is there a relationship wi=
th the MIB revision?

[Senthil2] Not directly, but there is some overlap of information that can =
be obtained by using a MIB and the logging mechanisms.


3.  Scope

   This document provides the information model to be used for logging
   the NAT devices including Carrier Grade NAT (CGN) events.  This
                   ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
SD: This sentence seems somewhat turned around - "logging events", not "log=
ging the NAT devices".
[Senthil] Agree, I will change this to "logging the NAT events".

Thanks.

   document focuses exclusively on the specification of IPFIX IE's.
   This document does not provide guidance on the transport protocol
   like TCP, UDP or SCTP that is to be used to log NAT events.  The log
   events SHOULD NOT be lost but the choice of the actual transport
   protocol is beyond the scope of this document.

SD: I'm not understanding why this last sentence is needed, especially with=
 a normative requirement for what you do when you are doing something outsi=
de the scope of the document ...
[Senthil] Are you objecting to the second part of the last sentence "the ch=
oice of actual transport=85", I think the requirement is that the LOG event=
s should not be lost is valid.

I'm sorry, my question wasn't clear. What I intended to say was that I was =
confused because the text said "not providing guidance on the choice of a t=
ransport protocol", but then provided a requirement about the implications =
of that choice (using a SHOULD).

So let me try to be clearer. I think what you're saying is

- you can use any transport protocol, but you SHOULDn't lose anything

I'm thinking this may be underspecified, although I don't know what IPFIX u=
sually expects from transport protocols, so please be patient.

First, I'm confused by the SHOULD with no qualification. When is it OK to l=
ose LOG events?
[Senthil] Ideally you should never lose the logs, but if the box crashes or=
 an irrecoverable error happens.


Second, you're not giving guidance on selecting a transport protocol, but y=
ou are giving guidance about expecting a reliable data channel, whether MUS=
T be reliable or SHOULD be reliable. Are there other transport characterist=
ics that you expect? For instance, is in-order delivery assumed? Is duplica=
te detection by IPFIX assumed (if a log arrives twice, does IPFIX notice)?
[Senthil2] There is no need for in-order delivery, the collector should be =
able to detect two identical events at the exact same time stamp as duplica=
tes. The only transport characteristic required is the reliability.


Third, are IPFIX implementations so transport protocol-agnostic that if my =
NAT device decides to to send logs using SCTP with partial reliability, I s=
hould expect that to work with any collector that implements this specifica=
tion?
[Senthil2] One of the reasons for not giving the guidance is that IPFIX was=
 initially SCTP only but in the latest RFC 7011, IPFIX can be transported u=
sing TCP/UDP/SCTP and others. As long as both the devices are using IPFIX,
and the receiving collector is able to parse and understand SCTP, it should=
 work. There is a little bit of configuration required, I would think, to t=
ell the NAT device on what protocol and port to use, to specify where the c=
ollector is
listening.



It happens that I co-chaired MEDIACTRL when the specification said "TCP or =
SCTP", and got feedback during AD evaluation that if we didn't pick a manda=
tory to implement transport protocol, that wouldn't guarantee interoperatio=
n between two standard-conforming devices.

[Senthil2] Ok, I don=92t know if in this case, I could pick a transport pro=
tocol to use with IPFIX, since IPFIX allows that flexibility and NAT logs a=
re transported over IPFIX, people would expect that we support all the tran=
sport protocols that IPFIX supports. Let me know if you have better suggest=
ions on what the guidance should be.



   The existing IANA IPFIX IEs registry [IPFIX-IANA] already has
   assignments for many NAT logging events.  For convenience, this
   document uses those same IEs.  However, as stated earlier, this
   document is not defining IPFIX or NetFlow v9 as the framework for
   logging.  Rather, the information contained in these elements is

SD: I got lost on "these elements" - is that "the elements in the existing =
registry"
[Senthil] Yes. How about "Rather, the information elements as defined in th=
e IPFIX-IANA registry is within the scope of this document"?

I think that's "are within", but yes, that works. Thanks.

   within the scope of this document.

   This document assumes that the NAT device will use the existing IPFIX
   framework to send the log events to the collector.  This would mean
   that the NAT device will specify the template that it is going to use
   for each of the events.  The templates can be of varying length and
   there could be multiple templates that a NAT device could use to log
   the events.

   The implementation details of the collector application is beyond the
   scope of this document.

   The optimization of logging the NAT events are left to the
                                              ^^^
   implementation and are beyond the scope of this document.
                      ^^^
SD: It's a nit, but those "are"s should be "is"s.
[Senthil] Ok.

Thanks.

4.  Applicability

   NAT logging based on IPFIX uses binary encoding and hence is very
   efficient.  IPFIX based logging is recommended for environments where
   a high volume of logging is required, for example, where per-flow
   logging is needed.  However, IPFIX based logging requires a collector
   that processes the binary data and requires a network management
   application that converts this binary data to a human readable
   format.

5.  Event based logging

   An event in a NAT device can be viewed as a happening as it relates
                                               ^^^^^^^^^
SD: Is this "a state transition"? I found "a happening" somewhat odd.
[Senthil] Yes, I can rephrase this as "viewed as a state transition as it r=
elates to" or "viewed as an action as it relates to", if that is ok.

If "a state transition" is correct, I'd prefer that (if it's correct :-) ).

   to the management of NAT resources.  The creation and deletion of NAT
   sessions and bindings are examples of events as it results in the
   resources (addresses and ports) being allocated or freed.  The events
   can happen either through the processing of data packets flowing
   through the NAT device or through an external entity installing
   policies on the NAT router or as a result of an asynchronous event
   like a timer.  The list of events are provided in Section 4.1.  Each
   of these events SHOULD be logged, unless they are administratively
   prohibited.  A NAT device MAY log these events to multiple collectors
   if redundancy is required.  The network administrator will specify
   the collectors to which the log records are to be sent.

   A collector may receive NAT events from multiple CGN devices and
   should be able to distinguish between the devices.  Each CGN device
   ^^^^^^
SD: I'm not sure why this isn't a SHOULD, or even a MUST.

   should have a unique source ID to identify themselves.  The source ID
   ^^^^^^
SD: Again, I'm not sure why this isn't a SHOULD, or even a MUST.

[Senthil] Well, this is NOT a statement for a NAT device, instead it is a c=
ollector that some application writer will
develop.

Don't you think you can levy requirements about that on the collector? I do=
n't understand.
[Senthil2] This document was written for how the NAT devices should send th=
eir logs and their formats. I am not sure if I am opening a can of worms, b=
y
Starting to specify what the collector should do as part of this document.

But beyond that, what I THINK the text is saying, is that multiple CGN devi=
ces can ("may") send to a single collector,
[Senthil2] Yes.

that none of the CDN devices have to have a unique source ID to identify th=
emselves ("should", but not "must"),
         ^^^^^
[Senthil2] No, that is not what the text is saying . In fact it says the op=
posite,

"Each CGN device should have a unique source ID to identify themselves."

and that the collector is still expected to be able to distinguish among lo=
gs coming from multiple CGNs ("should").

[Senthil2] Yes, the collector should be able to distinguish the records com=
ing in from distinct sources. This is a generic IPFIX requirement,
That a collector is able to handle multiple sources. Maybe I should remove =
this text on the collector as it seems to cause more confusion?


Am I misreading this?

If not, do you think that works?

[Senthil2] Please see above, let me know if I misunderstood what you were a=
sking.


   is part of the IPFIX template and data exchange.

   Prior to logging any events, the NAT device MUST send the template of
   the record to the collector to advertise the format of the data
   record that it is using to send the events.  The templates can be
   exchanged as frequently as required given the reliability of the
   connection.  There SHOULD be a configurable timer for controlling the
   template refresh.  NAT device SHOULD combine as many events as
   possible in a single packet to effectively utilize the network
   bandwidth.

5.1.  Logging of destination information

   Logging of destination information in a NAT event has been discussed
   in [RFC6302] and [RFC6888].  Logging of destination information
   increases the size of each record and increases the need for storage
   considerably.  It increases the number of log events generated
   because when the same user connects to a different destination, it
   results in a log record per destination address.  Logging of
   destination information also results in the loss of privacy and hence
   should be done with caution.  However, this draft provides the
   necessary fields to log the destination information in cases where
   they are required to be logged.

5.2.  Information Elements

   The templates could contain a subset of the Information Elements(IEs)
   shown in Table 1 depending upon the event being logged.  For example
   a NAT44 session creation template record will contain,
                                            ^^^^
SD: Is this the only possible NAT44 template? If so, fine, but if not, perh=
aps "could contain", or "typically contains"?

[Senthil] Yes, this is all the information that a NAT44 need to export as i=
t is the least common denominator.

My question is whether any other IEs might be added in the future, I think.=
 If not, "will" is OK, but "MUST" would be clearer.

[Senthil2] I think this is the base information required, but difficult to =
predict what will be added in the future, so I am going to leave it as is, =
unless you have objection.


   {sourceIPv4Adress, postNATSourceIPv4Address, destinationIpv4Address,
   postNATDestinationIPv4Address, sourceTransportPort,
   postNAPTSourceTransportPort, destinationTransportPort,
   postNAPTDestTransportPort, internalAddressRealm, natEvent, timeStamp}

   An example of the actual event data record is shown below - in a
   readable form

   {192.168.16.1, 201.1.1.100, 207.85.231.104, 207.85.231.104, 14800,
   1024, 80, 80, 0, 1, 09:20:10:789}

   A single NAT device could be exporting multiple templates and the
   collector should support receiving multiple templates from the same
   source.observationTimeMilliseconds

   The following is the table of all the IE's that a CGN device would
   need to export the events.  The formats of the IE's and the IPFIX IDs
   are listed below.

SD: I noticed that some IEs below have a name that matches http://www.iana.=
org/assignments/ipfix/ipfix.xhtml#ipfix-information-elements for the same I=
PFIX ID number, but others do not ("timeStamp" here doesn't match "observat=
ionTimeMilliseconds", but both are IPFIX ID 323, aren't they?) Is there a r=
eason to use names that don't match the IANA registry?

[Senthil] Good question, in case of timeStamp, I was looking for something =
that already existed in the IPFIX registry rather than asking for a new one=
. However, the terminology of "observationTimeMilliseconds" is not the term=
inology that we use in the NAT drafts/rfc's. So I am open to suggestions he=
re. I can clarify in the description that is called observationTimeMilliSec=
onds". The other field is internalAddressRealm and externalAddresRealm, thi=
s is the terminology that we used in NAT MIB, syslog and other documents. H=
owever, when we defined the IPFIX IE, we didn=92t stick to the same termino=
logy, so I don=92t know if I can go and ask the IPFIX IANA to change the na=
me. Again I am open to suggestions, the dillema is whether I should stick t=
o the existing IPFIX IANA terminology or the behave documents terminology.

I'm way out of my depth on this one (sorry!).

Fortunately, the next stop for an AD-sponsored IPFIX specification is the I=
PFIX review team. Could you just add a note pointing this question out, and=
 asking if they have any suggestions?

[Senthil2] I will send out an email to the IPFIX mailing list and to the pe=
ople who reviewed it from the IPFIX WG.


   +----------------------------------+--------+-------+---------------+
   |            Field Name            |   Size |  IANA |  Description  |
   |                                  | (bits) | IPFIX |               |
   |                                  |        |    ID |               |
   +----------------------------------+--------+-------+---------------+
   |            timeStamp             |     64 |   323 |  System Time  |
   |                                  |        |       |    when the   |
   |                                  |        |       |     event     |
   |                                  |        |       |    occured.   |
   |          natInstanceId           |     32 |   TBD |  NAT Instance |
   |                                  |        |       |   Identifier  |
   |              vlanID              |     16 |    58 |   VLAN ID in  |
   |                                  |        |       |    case of    |
   |                                  |        |       |  overlapping  |
   |                                  |        |       |    networks   |
   |           ingressVRFID           |     32 |   234 |   VRF ID in   |
   |                                  |        |       |    case of    |
   |                                  |        |       |  overlapping  |
   |                                  |        |       |    networks   |
   |        sourceIPv4Address         |     32 |     8 |  Source IPv4  |
   |                                  |        |       |    Address    |
   |     postNATSourceIPv4Address     |     32 |   225 |   Translated  |
   |                                  |        |       |  Source IPv4  |
   |                                  |        |       |    Address    |
   |        protocolIdentifier        |      8 |     4 |   Transport   |
   |                                  |        |       |    protocol   |
   |       sourceTransportPort        |     16 |     7 |  Source Port  |
   |   postNAPTsourceTransportPort    |     16 |   227 |   Translated  |
   |                                  |        |       |  Source port  |
   |      destinationIPv4Address      |     32 |    12 |  Destination  |
   |                                  |        |       |  IPv4 Address |
   |  postNATDestinationIPv4Address   |     32 |   226 |   Translated  |
   |                                  |        |       |      IPv4     |
   |                                  |        |       |  destination  |
   |                                  |        |       |    address    |
   |     destinationTransportPort     |     16 |    11 |  Destination  |
   |                                  |        |       |      port     |
   | postNAPTdestinationTransportPort |     16 |   228 |   Translated  |
   |                                  |        |       |  Destination  |
   |                                  |        |       |      port     |
   |        sourceIPv6Address         |     27 |   128 |  Source IPv6  |
   |                                  |        |       |    address    |
   |      destinationIPv6Address      |    128 |    28 |  Destination  |
   |                                  |        |       |  IPv6 address |
   |     postNATSourceIPv6Address     |    128 |   281 |   Translated  |
   |                                  |        |       |  source IPv6  |
   |                                  |        |       |    addresss   |
   |  postNATDestinationIPv6Address   |    128 |   282 |   Translated  |
   |                                  |        |       |  Destination  |
   |                                  |        |       |  IPv6 address |
   |       internalAddressRealm       |      8 |   229 |     Source    |
   |                                  |        |       | Address Realm |
   |       externalAddressRealm       |      8 |   TBD |  Destination  |
   |                                  |        |       | Address Realm |
   |             natEvent             |      8 |   230 | Type of Event |
   |          portRangeStart          |     16 |   361 |   Allocated   |
   |                                  |        |       |   port block  |
   |                                  |        |       |     start     |
   |           portRangeEnd           |     16 |   362 |   Allocated   |
   |                                  |        |       |   Port block  |
   |                                  |        |       |      end      |
   |            natPoolID             |     32 |   283 |    NAT pool   |
   |                                  |        |       |   Identifier  |
   |          natLimitEvent           |     32 |   TBD |  Limit event  |
   |                                  |        |       |   identifier  |
   +----------------------------------+--------+-------+---------------+

                      Table 1: Template format Table

5.3.  Definition of NAT Events

   The following are the list of NAT events and the proposed event
   values.  The list can be expanded in the future as necessary.  The
   data record will have the corresponding natEvent value to identify
   the event that is being logged.

                   +--------------------------+--------+
                   |        Event Name        | Values |
                   +--------------------------+--------+
                   |   NAT44 Session create   |      1 |
                   |   NAT44 Session delete   |      2 |
                   | NAT Addresses exhausted  |      3 |
                   |   NAT64 Session create   |      4 |
                   |   NAT64 Session delete   |      5 |
                   |     NAT44 BIB create     |      6 |
                   |     NAT44 BIB delete     |      7 |
                   |     NAT64 BIB create     |      8 |
                   |     NAT64 BIB delete     |      9 |
                   |   NAT ports exhausted    |     10 |
                   |      Quota exceeded      |     11 |
                   |  Address binding create  |     12 |
                   |  Address binding delete  |     13 |
                   |  Port block allocation   |     14 |
                   | Port block de-allocation |     15 |
                   |    Threshold reached     |     16 |
                   +--------------------------+--------+

                        Table 2: NAT Event ID table

5.4.  Quota exceeded Event types

   The following table shows the sub event types for the Quota exceeded
   or limits reached event.  The events that can be reported are the
   Maximum session entries limit reached, Maximum BIB entries limit
   reached, Maximum session/BIB entries per user limit reached and
   maximum subscribers or hosts limit reached.

            +---------------------------------------+--------+
            |       Quota Exceeded Event Name       | Values |
            +---------------------------------------+--------+
            |        Maximum Session entries        |      1 |
            |          Maximum BIB entries          |      2 |
            |        Maximum entries per user       |      3 |
            |  Maximum active hosts or subscribers  |      4 |
            |  Maximum fragments pending reassembly |      5 |
            +---------------------------------------+--------+

                    Table 3: Quota Exceeded event table

5.5.  Threshold reached Event types

   The following table shows the sub event types for the threshold
   reached event.  The administrator can configure the thresholds and
   whenever the threshold is reached or exceeded, the corresponding
   events are generated.

   The address pool high threshold event will be reported when the
   address pool reaches a high water mark as defined by the operator.
   This will sever as an indication that the operator might have to add
   more addresses to the pool or an indication that the subsequent users
   may be denied NAT translation mappings.

   The address and port mapping high threshold event is generated, when
   the number of ports in the configured address pool has reached a
   configured threshold.

   The per-user address and port mapping high threshold is generated
   when a single user uses more address and port mapping than a
   configured threshold.

   +---------------------------------------------------------+--------+
   |              Threshold Exceeded Event Name              | Values |
   +---------------------------------------------------------+--------+
   |            Address pool high threshold event            |      1 |
   |             Address pool low threshold event            |      2 |
   |      Address and port mapping high threshold event      |      3 |
   |  Address and port mapping per user high threshold event |      4 |
   |       Global Address mapping high threshold event       |      5 |
   +---------------------------------------------------------+--------+

                      Table 4: Threshold event table

5.6.  Templates for NAT Events

   The following is the template of events that will have to logged.
                                                ^^^^^^^^^^^^^^^^^^^

SD: I think this is a nit, but the sentence is garbled. "will be logged"?

   The events below are identified at the time of this writing but the
   events are expandable.  Depending on the implementation and
   ^^^^^^^^^^^^^^^^^^^^^
SD: this is a nit, but "set of events is extensible", I think.

[Senthil] Agree. (to both comments).

Thanks,

   configuration various IE's specified can be included or ignored.

5.6.1.  NAT44 create and delete session events

   These events will be generated when a NAT44 session is created or
   deleted.  The template will be the same, the natEvent will indicate
   whether it is a create or a delete event.  The following is a
   template of the event.

   The destination address and port information is optional as required
   by [RFC6888].  However, when the destination information is
   suppressed, the session log event contains the same information as
   the BIB event.  In such cases, the NAT device SHOULD NOT send both
   BIB and session events.

      +----------------------------------+-------------+-----------+
      |            Field Name            | Size (bits) | Mandatory |
      +----------------------------------+-------------+-----------+
      |            timeStamp             |          64 |    Yes    |
      |          natInstanceID           |          32 |     No    |
      |       vlanID/ingressVRFID        |          32 |     No    |
      |        sourceIPv4Address         |          32 |    Yes    |
      |     postNATSourceIPv4Address     |          32 |    Yes    |
      |        protocolIdentifier        |           8 |    Yes    |
      |       sourceTransportPort        |          16 |    Yes    |
      |   postNAPTsourceTransportPort    |          16 |    Yes    |
      |      destinationIPv4Address      |          32 |     No    |
      |  postNATDestinationIPv4Address   |          32 |     No    |
      |     destinationTransportPort     |          16 |     No    |
      | postNAPTdestinationTransportPort |          16 |     No    |
      |       internalAddressRealm       |           8 |     No    |
      |       externalAddressRealm       |           8 |     No    |
      |             natEvent             |           8 |    Yes    |
      +----------------------------------+-------------+-----------+

               Table 5: NAT44 Session delete/create template

5.6.2.  NAT64 create and delete session events

   These events will be generated when a NAT64 session is created or
   deleted.  The following is a template of the event.

      +----------------------------------+-------------+-----------+
      |            Field Name            | Size (bits) | Mandatory |
      +----------------------------------+-------------+-----------+
      |            timeStamp             |          64 |    Yes    |
      |          natInstanceID           |          32 |     No    |
      |       vlanID/ingressVRFID        |          32 |     No    |
      |        sourceIPv6Address         |         128 |    Yes    |
      |     postNATSourceIPv4Address     |          32 |    Yes    |
      |        protocolIdentifier        |           8 |    Yes    |
      |       sourceTransportPort        |          16 |    Yes    |
      |   postNAPTsourceTransportPort    |          16 |    Yes    |
      |      destinationIPv6Address      |         128 |     No    |
      |  postNATDestinationIPv4Address   |          32 |     No    |
      |     destinationTransportPort     |          16 |     No    |
      | postNAPTdestinationTransportPort |          16 |     No    |
      |       internalAddressRealm       |           8 |     No    |
      |       externalAddressRealm       |           8 |     No    |
      |             natEvent             |           8 |    Yes    |
      +----------------------------------+-------------+-----------+

            Table 6: NAT64 session create/delete event template

5.6.3.  NAT44 BIB create and delete events

   These events will be generated when a NAT44 Bind entry is created or
   deleted.  The following is a template of the event.

         +-----------------------------+-------------+-----------+
         |          Field Name         | Size (bits) | Mandatory |
         +-----------------------------+-------------+-----------+
         |          timeStamp          |          64 |    Yes    |
         |        natInstanceID        |          32 |     No    |
         |     vlanID/ingressVRFID     |          32 |     No    |
         |      sourceIPv4Address      |          32 |    Yes    |
         |   postNATSourceIPv4Address  |          32 |    Yes    |
         |      protocolIdentifier     |           8 |     No    |
         |     sourceTransportPort     |          16 |     No    |
         | postNAPTsourceTransportPort |          16 |     No    |
         |     internalAddressRealm    |           8 |     No    |
         |     externalAddressRealm    |           8 |     No    |
         |           natEvent          |           8 |    Yes    |
         +-----------------------------+-------------+-----------+

              Table 7: NAT44 BIB create/delete event template

5.6.4.  NAT64 BIB create and delete events

   These events will be generated when a NAT64 Bind entry is created or
   deleted.  The following is a template of the event.

         +-----------------------------+-------------+-----------+
         |          Field Name         | Size (bits) | Mandatory |
         +-----------------------------+-------------+-----------+
         |          timeStamp          |          64 |    Yes    |
         |        natInstanceID        |          32 |     No    |
         |     vlanID/ingressVRFID     |          32 |     No    |
         |      sourceIPv6Address      |         128 |    Yes    |
         |   postNATSourceIPv4Address  |          32 |    Yes    |
         |      protocolIdentifier     |           8 |     No    |
         |     sourceTransportPort     |          16 |     No    |
         | postNAPTsourceTransportPort |          16 |     No    |
         |     internalAddressRealm    |           8 |     No    |
         |     externalAddressRealm    |           8 |     No    |
         |           natEvent          |           8 |    Yes    |
         +-----------------------------+-------------+-----------+

              Table 8: NAT64 BIB create/delete event template

5.6.5.  Addresses Exhausted event

   This event will be generated when a NAT device runs out of global
   IPv4 addresses in a given pool of addresses.  Typically, this event
   would mean that the NAT device wont be able to create any new
                                  ^^^^
SD: "won't"

[Senthil] Ok.

Thanks,


   translations until some addresses/ports are freed.  This event SHOULD
   be rate limited as many packets hitting the device at the same time
   will trigger a burst of addresses exhausted events.

   The following is a template of the event.  Note that either the NAT
   pool name or the nat pool identifier should be logged, but not both.

SD: I lack understanding, but I didn't see anything that looked like a NAT =
pool name in the template. Did I miss something?

[Senthil] We decided not to use a string like a pool name instead use a poo=
lID, which is a unique identifier for each pool name. The reason being that=
 the logs could become fairly large
If we have to carry the names and some of the NAT engines implement this in=
 the hardware that lacks the string processing capability.

OK, that helps. I'm understanding that a different template might have incl=
uded a pool name, but not a poolID, is that right?

I'm somewhat uneasy about the "either should be logged, but not both" text.

[Senthil2] That text is not relevant anymore and should be removed, there w=
as a time we had both poolName & poolID.


Same question as usual - is this an RFC 2119 SHOULD that helps with interop=
eration, or is this about an implementation choice?

If it's an RFC 2119 SHOULD, robust collectors will need to do something if =
a log arrives with both a pool name and a poolID. If it's a MUST, a collect=
or wouldn't accept the log (however the collector would decide to do that).

[Senthil2] As you see in the below template, if the mandatory field is Yes,=
 then the NAT device MUST log it. If the field is not mandatory, then the n=
at device can choose to send it or not. But the actual template will that t=
he device sends indicates what the device is sending and the data set will =
correspond to the template, and the collector will correlate the template a=
nd the data sets.

If it's not an RFC 2119 SHOULD, but just implementation guidance, the expla=
nation you provided would be more helpful (something like "could include a =
pool name, but some NAT engines are implemented in hardware that lacks stri=
ng processing capability, and these are permitted to substitute a poolID. T=
here's no reason to provide both a pool name and a poolID").

                +---------------+-------------+-----------+
                |   Field Name  | Size (bits) | Mandatory |
                +---------------+-------------+-----------+
                |   timeStamp   |          64 |    Yes    |
                | natInstanceID |          32 |     No    |
                |    natEvent   |           8 |    Yes    |
                |   natPoolID   |          32 |    Yes    |
                +---------------+-------------+-----------+

                 Table 9: Address Exhausted event template

5.6.6.  Ports Exhausted event

   This event will be generated when a NAT device runs out of ports for
   a global IPv4 address.  Port exhaustion shall be reported per
   protocol (UDP, TCP etc).  This event SHOULD be rate limited as many
   packets hitting the device at the same time will trigger a burst of
   port exhausted events.

   The following is a template of the event.

          +--------------------------+-------------+-----------+
          |        Field Name        | Size (bits) | Mandatory |
          +--------------------------+-------------+-----------+
          |        timeStamp         |          64 |    Yes    |
          |      natInstanceID       |          32 |     No    |
          |         natEvent         |           8 |    Yes    |
          | postNATSourceIPv4Address |          32 |    Yes    |
          |    protocolIdentifier    |           8 |    Yes    |
          +--------------------------+-------------+-----------+

                 Table 10: Ports Exhausted event template

5.6.7.  Quota exceeded events

   This event will be generated when a NAT device cannot allocate
   resources as a result of an administratively defined policy.  The
   quota exceeded event templates are described below
                                                     ^
SD: missing period
[Senthil] Ok.

Thanks,

5.6.7.1.  Maximum session entries exceeded

   The maximum session entries exceeded is generated when the
   administratively configured limit is reached.  The following is the
   template of the event.

               +-----------------+-------------+-----------+
               |    Field Name   | Size (bits) | Mandatory |
               +-----------------+-------------+-----------+
               |    timeStamp    |          64 |    Yes    |
               |  natInstanceID  |          32 |     No    |
               |     natEvent    |           8 |    Yes    |
               |  natLimitEvent  |          32 |    Yes    |
               | configuredLimit |          32 |    Yes    |
               +-----------------+-------------+-----------+

             Table 11: Session Entries Exceeded event template

5.6.7.2.  Maximum BIB entries exceeded

   The maximum BIB entries exceeded is generated when the
   administratively configured limit is reached.  The following is the
   template of the event.

               +-----------------+-------------+-----------+
               |    Field Name   | Size (bits) | Mandatory |
               +-----------------+-------------+-----------+
               |    timeStamp    |          64 |    Yes    |
               |  natInstanceID  |          32 |     No    |
               |     natEvent    |           8 |    Yes    |
               |  natLimitEvent  |          32 |    Yes    |
               | configuredLimit |          32 |    Yes    |
               +-----------------+-------------+-----------+

               Table 12: BIB Entries Exceeded event template

5.6.7.3.  Maximum entries per user exceeded

   This event is generated when a single user reaches the
   administratively configured limit.  The following is the template of
   the event.

           +---------------------+-------------+---------------+
           |      Field Name     | Size (bits) |   Mandatory   |
           +---------------------+-------------+---------------+
           |      timeStamp      |          64 |      Yes      |
           |    natInstanceID    |          32 |       No      |
           |       natEvent      |           8 |      Yes      |
           |    natLimitEvent    |          32 |      Yes      |
           |   configuredLimit   |          32 |      Yes      |
           | vlanID/ingressVRFID |          32 |       No      |
           |  sourceIPv4 address |          32 | Yes for NAT44 |
           |  sourceIPv6 address |         128 | Yes for NAT64 |
           +---------------------+-------------+---------------+

            Table 13: Per-user Entries Exceeded event template

5.6.7.4.  Maximum active host or subscribers exceeded

   This event is generated when the number of allowed hosts or
   subscribers reaches the administratively configured limit.  The
   following is the template of the event.

               +-----------------+-------------+-----------+
               |    Field Name   | Size (bits) | Mandatory |
               +-----------------+-------------+-----------+
               |    timeStamp    |          64 |    Yes    |
               |  natInstanceID  |          32 |     No    |
               |     natEvent    |           8 |    Yes    |
               |  natLimitEvent  |          32 |    Yes    |
               | configuredLimit |          32 |    Yes    |
               +-----------------+-------------+-----------+

        Table 14: Maximum hosts/subscribers Exceeded event template

5.6.7.5.  Maximum fragments pending reassembly exceeded

   This event is generated when the number of fragments pending
   reassembly reaches the administratively configured limit.  The
   following is the template of the event.

          +----------------------+-------------+---------------+
          |      Field Name      | Size (bits) |   Mandatory   |
          +----------------------+-------------+---------------+
          |      timeStamp       |          64 |      Yes      |
          |    natInstanceID     |          32 |       No      |
          |       natEvent       |           8 |      Yes      |
          |    natLimitEvent     |          32 |      Yes      |
          |   configuredLimit    |          32 |      Yes      |
          | internalAddressRealm |           8 |      Yes      |
          | vlanID/ingressVRFID  |          32 |       No      |
          |  sourceIPv4 address  |          32 | Yes for NAT44 |
          |  sourceIPv6 address  |         128 | Yes for NAT64 |
          +----------------------+-------------+---------------+

       Table 15: Maximum fragments pending reassembly Exceeded event
                                 template

5.6.8.  Threshold reached events

   This event will be generated when a NAT device reaches a operator
   configured threshold when allocating resources.  The threshold
   reached events are described in the section above.  The following is
   a template of the individual events.

5.6.8.1.  Address pool high or low threshold reached

   This event is generated when the high or low threshold is reached for
   the address pool.  The template is the same for both high and low
   threshold events

              +-------------------+-------------+-----------+
              |     Field Name    | Size (bits) | Mandatory |
              +-------------------+-------------+-----------+
              |     timeStamp     |          64 |    Yes    |
              |   natInstanceID   |          32 |     No    |
              |      natEvent     |           8 |    Yes    |
              | natThresholdEvent |          32 |    Yes    |
              |     natPoolID     |          32 |    Yes    |
              |  configuredLimit  |          32 |    Yes    |
              +-------------------+-------------+-----------+

     Table 16: Address pool high/low threshold reached event template

5.6.8.2.  Address and port high threshold reached

   This event is generated when the high threshold is reached for the
   address pool and ports.

              +-------------------+-------------+-----------+
              |     Field Name    | Size (bits) | Mandatory |
              +-------------------+-------------+-----------+
              |     timeStamp     |          64 |    Yes    |
              |   natInstanceID   |          32 |     No    |
              |      natEvent     |           8 |    Yes    |
              | natThresholdEvent |          32 |    Yes    |
              |  configuredLimit  |          32 |    Yes    |
              +-------------------+-------------+-----------+

       Table 17: Address port high threshold reached event template

5.6.8.3.  Per-user Address and port high threshold reached

   This event is generated when the high threshold is reached for the
   per-user address pool and ports.

           +---------------------+-------------+---------------+
           |      Field Name     | Size (bits) |   Mandatory   |
           +---------------------+-------------+---------------+
           |      timeStamp      |          64 |      Yes      |
           |    natInstanceID    |          32 |       No      |
           |       natEvent      |           8 |      Yes      |
           |  natThresholdEvent  |          32 |      Yes      |
           |   configuredLimit   |          32 |      Yes      |
           | vlanID/ingressVRFID |          32 |       No      |
           |  sourceIPv4 address |          32 | Yes for NAT44 |
           |  sourceIPv6 address |         128 | Yes for NAT64 |
           +---------------------+-------------+---------------+

   Table 18: Per-user Address port high threshold reached event template

5.6.8.4.  Global Address mapping high threshold reached

   This event is generated when the high is reached for the per-user
   address pool and ports.  This is generated only by NAT devices that
   use a address pooling behavior of paired.

             +---------------------+-------------+-----------+
             |      Field Name     | Size (bits) | Mandatory |
             +---------------------+-------------+-----------+
             |      timeStamp      |          64 |    Yes    |
             |    natInstanceID    |          32 |     No    |
             |       natEvent      |           8 |    Yes    |
             |  natThresholdEvent  |          32 |    Yes    |
             |   configuredLimit   |          32 |    Yes    |
             | vlanID/ingressVRFID |          32 |     No    |
             +---------------------+-------------+-----------+

       Table 19: Global Address mapping high threshold reached event
                                 template

5.6.9.  Address binding create and delete events

   These events will be generated when a NAT device binds a local
   address with a global address and when the global address is freed.
   This binding event happens when the first packet of the first flow
   from a host in the private realm.

     +--------------------------------+-------------+---------------+
     |           Field Name           | Size (bits) |   Mandatory   |
     +--------------------------------+-------------+---------------+
     |           timeStamp            |          64 |      Yes      |
     |         natInstanceID          |          32 |       No      |
     |            natEvent            |           8 |      Yes      |
     |       sourceIPv4 address       |          32 | Yes for NAT44 |
     |       sourceIPv6 address       |         128 | Yes for NAT64 |
     | Translated Source IPv4 Address |          32 |      Yes      |
     +--------------------------------+-------------+---------------+

                  Table 20: NAT Address Binding template

5.6.10.  Port block allocation and de-allocation

   This event will be generated when a NAT device allocates/de-allocates
   ports in a bulk fashion, as opposed to allocating a port on a per
   flow basis.

   portRangeStart represents the starting value of the range.

   portRangeEnd represents the ending value of the range.

   NAT devices would do this in order to reduce logs and potentially to
   limit the number of connections a subscriber is allowed to use.  In
   the following Port Block allocation template, the portRangeStart and
   portRangeEnd must be specified.


Sivakumar & Penno        Expires August 15, 2014               [Page 17]

Internet-Draft          IPFIX IEs for NAT logging          February 2014

   It is up to the implementation to choose to consolidate log records
   in case two consecutive port ranges for the same user are allocated
   or freed.

     +--------------------------------+-------------+---------------+
     |           Field Name           | Size (bits) |   Mandatory   |
     +--------------------------------+-------------+---------------+
     |           timeStamp            |          64 |      Yes      |
     |         natInstanceID          |          32 |       No      |
     |            natEvent            |           8 |      Yes      |
     |       sourceIPv4 address       |          32 | Yes for NAT44 |
     |       sourceIPv6 address       |         128 | Yes for NAT64 |
     | Translated Source IPv4 Address |          32 |      Yes      |
     |         portRangeStart         |          16 |      Yes      |
     |          portRangeEnd          |          16 |       No      |
     +--------------------------------+-------------+---------------+

            Table 21: NAT Port Block Allocation event template

6.  Encoding

6.1.  IPFIX

   This document uses IPFIX as the encoding mechanism to describe the
   logging of NAT events.  However, the information that should be
   logged SHOULD be the same irrespective of what kind of encoding
   scheme is used.  IPFIX is chosen because is it an IETF standard that
   meets all the needs for a reliable logging mechanism.  IPFIX provides
   the flexibility to the logging device to define the data sets that it
   is logging.  The IEs specified for logging MUST be the same
   irrespective of the encoding mechanism used.

7.  Acknowledgements

   Thanks to Dan Wing, Selvi Shanmugam, Mohamed Boucadir, Jacni Qin
   Ramji Vaithianathan, Simon Perreault, Jean-Francois Tremblay, Paul
   Aitken and Julia Renouard for their review and comments.

8.  IANA Considerations

   The following information elements are requested from IANA IPFIX
   registry.

   natInstanceId

   externalAddressRealm

   natLimitEvent

9.  Management Considerations

   This section considers requirements for management of the log system
   to support logging of the events described above.  It first covers
   requirements applicable to log management in general.  Any additional
   standardization required to fullfil these requirements is out of
   scope of the present document.  Some management considerations is
   covered in [I-D.behave-syslog-nat-logging].  This document covers the
   additional considerations.

9.1.  Ability to collect events from multiple NAT devices

   An IPFIX collector should be able to collect events from multiple NAT
   devices and be able to decipher events based on the sourceID in the
   IPFIX header.

9.2.  Ability to suppress events

   The exhaustion events can be overwhelming during traffic bursts and
   hence should be handled by the NAT devices to rate limit them before
   sending them to the collectors.  For eg. when the port exhaustion
   happens during bursty conditions, instead of sending a port
   exhaustion event for every packet, the exhaustion events should be
   rate limited by the NAT device.

10.  Security Considerations

   None.

11.  References

11.1.  Normative References

   [RFC2119]  Bradner, S., "Key words for use in RFCs to Indicate
              Requirement Levels", BCP 14, RFC 2119, March 1997.

   [RFC2663]  Srisuresh, P. and M. Holdrege, "IP Network Address
              Translator (NAT) Terminology and Considerations", RFC
              2663, August 1999.

   [RFC4787]  Audet, F. and C. Jennings, "Network Address Translation
              (NAT) Behavioral Requirements for Unicast UDP", BCP 127,
              RFC 4787, January 2007.

   [RFC5382]  Guha, S., Biswas, K., Ford, B., Sivakumar, S., and P.
              Srisuresh, "NAT Behavioral Requirements for TCP", BCP 142,
              RFC 5382, October 2008.

   [RFC6146]  Bagnulo, M., Matthews, P., and I. van Beijnum, "Stateful
              NAT64: Network Address and Protocol Translation from IPv6
              Clients to IPv4 Servers", RFC 6146, April 2011.

   [RFC6302]  Durand, A., Gashinsky, I., Lee, D., and S. Sheppard,
              "Logging Recommendations for Internet-Facing Servers", BCP
              162, RFC 6302, June 2011.

   [RFC6888]  Perreault, S., Yamagata, I., Miyakawa, S., Nakagawa, A.,
              and H. Ashida, "Common Requirements for Carrier-Grade NATs
              (CGNs)", BCP 127, RFC 6888, April 2013.

11.2.  Informative References

   [I-D.ietf-behave-syslog-nat-logging]
              Chen, Z., Zhou, C., Tsou, T., and T. Taylor, "Syslog
              Format for NAT Logging", draft-ietf-behave-syslog-nat-
              logging-06 (work in progress), January 2014.

   [IPFIX-IANA]
              IANA, "IPFIX Information Elements registry",
              <http://www.iana.org/assignments/ipfix><http://www.iana.org/a=
ssignments/ipfix>.

   [RFC5101bis]
              Claise, B. and B. Trammel, "Specification of the IP Flow
              Information eXport (IPFIX) Protocol for the Exchange of
              Flow Information", July 2013.

   [RFC5102bis]
              Claise, B. and B. Trammel, "Information Model for IP Flow
              Information eXport (IPFIX)", February 2013.

   [RFC5470]  Sadasivan, G., Brownlee, N., Claise, B., and J. Quittek,
              "Architecture for IP Flow Information Export", RFC 5470,
              March 2009.

Authors' Addresses

   Senthil Sivakumar
   Cisco Systems
   7100-8 Kit Creek Road
   Research Triangle Park, North Carolina  27709
   USA

   Phone: +1 919 392 5158

   Renaldo Penno
   Cisco Systems
   170 W Tasman Drive
   San Jose, California  95035
   USA

   Email: repenno@cisco.com<mailto:repenno@cisco.com>






















Sivakumar & Penno        Expires August 15, 2014               [Page 21]


--_000_CFAA34BB106C60ssenthilciscocom_
Content-Type: text/html; charset="Windows-1252"
Content-ID: <12465753C6F1454BAF9B301C472A7286@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-lin=
e-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-fami=
ly: Calibri, sans-serif; ">
<div>Hi Spencer,&nbsp;</div>
<div>Thanks for your comments again, please see inline [Senthil2].</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div style=3D"font-family:Calibri; font-size:11pt; text-align:left; color:b=
lack; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM:=
 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;=
 BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style=3D"font-weight:bold">From: </span>Spencer Dawkins &lt;<a href=
=3D"mailto:spencerdawkins.ietf@gmail.com">spencerdawkins.ietf@gmail.com</a>=
&gt;<br>
<span style=3D"font-weight:bold">Date: </span>Friday, May 23, 2014 5:05 PM<=
br>
<span style=3D"font-weight:bold">To: </span>Senthil Sivakumar &lt;<a href=
=3D"mailto:ssenthil@cisco.com">ssenthil@cisco.com</a>&gt;, &quot;<a href=3D=
"mailto:draft-ietf-behave-ipfix-nat-logging@tools.ietf.org">draft-ietf-beha=
ve-ipfix-nat-logging@tools.ietf.org</a>&quot; &lt;<a href=3D"mailto:draft-i=
etf-behave-ipfix-nat-logging@tools.ietf.org">draft-ietf-behave-ipfix-nat-lo=
gging@tools.ietf.org</a>&gt;<br>
<span style=3D"font-weight:bold">Cc: </span>&quot;<a href=3D"mailto:behave@=
ietf.org">behave@ietf.org</a>&quot; &lt;<a href=3D"mailto:behave@ietf.org">=
behave@ietf.org</a>&gt;<br>
<span style=3D"font-weight:bold">Subject: </span>Re: AD Evaluation of draft=
-ietf-behave-ipfix-nat-logging-03<br>
</div>
<div><br>
</div>
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<div class=3D"moz-cite-prefix">On 05/02/2014 02:20 PM, Senthil Sivakumar (s=
senthil) wrote:<br>
</div>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
>
<div>Hi Spencer,&nbsp;</div>
<div>Thanks for the thorough review.&nbsp;</div>
<div>Please see inline for [Senthil]. If you agree, I will submit another v=
ersion fixing all the issues raised and agreed upon. I will wait for your r=
esponse.</div>
</blockquote>
<br>
Hi, Senthil,<br>
<br>
Thanks for being responsive!<br>
<br>
Just as a high-order bit, many of the questions I asked are whether the dra=
ft uses &quot;required&quot; to mean &quot;this is the way it works&quot; -=
 there's a difference between &quot;the sender transmits a log&quot; and &q=
uot;the sender is required to transmit a log&quot;. Does that make sense?<b=
r>
<br>
Ths draft says it uses requirements language as per RFC 2119, and RFC 2119 =
says <br>
<br>
6. Guidance in the use of these Imperatives<br>
<br>
&nbsp;&nbsp; Imperatives of the type defined in this memo must be used with=
 care<br>
&nbsp;&nbsp; and sparingly.&nbsp; In particular, they MUST only be used whe=
re it is<br>
&nbsp;&nbsp; actually required for interoperation or to limit behavior whic=
h has<br>
&nbsp;&nbsp; potential for causing harm (e.g., limiting retransmisssions)&n=
bsp; For<br>
&nbsp;&nbsp; example, they must not be used to try to impose a particular m=
ethod<br>
&nbsp;&nbsp; on implementors where the method is not required for<br>
&nbsp;&nbsp; interoperability.<br>
<br>
It's also worth mentioning that RFC 2119 is silent on case for requirements=
 language, your requirements terminology section only shows upper case exam=
ples, and most of the cases I'm asking about are in lower case, which makes=
 it less clear whether you intend
 &quot;require&quot; to be an RFC 2119 requirement word or not. This is a c=
ontinuing source of controversy in the IETF, especially during cross-area r=
eview - my suggestion is that you either change the requirements language s=
tatement to include a statement about whether
 lower-case versions are intended as requirements language, or don't use th=
e lower-case terms in the document.<br>
<br>
I'll try to be clear in my detailed comments, but that's often what I'm try=
ing to get at.</div>
</div>
</span>
<div><br>
</div>
<div>[Senthil2] Ok, thanks.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
>
<div>Thanks</div>
<div>Senthil</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div style=3D"font-family:Calibri; font-size:11pt;
          text-align:left; color:black; BORDER-BOTTOM: medium none;
          BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT:
          0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;
          BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style=3D"font-weight:bold">From: </span>Spencer Dawkins &lt;<a moz-do=
-not-send=3D"true" href=3D"mailto:spencerdawkins.ietf@gmail.com">spencerdaw=
kins.ietf@gmail.com</a>&gt;<br>
<span style=3D"font-weight:bold">Date: </span>Thursday, May 1, 2014 4:25 PM=
<br>
<span style=3D"font-weight:bold">To: </span>&quot;<a moz-do-not-send=3D"tru=
e" href=3D"mailto:draft-ietf-behave-ipfix-nat-logging@tools.ietf.org">draft=
-ietf-behave-ipfix-nat-logging@tools.ietf.org</a>&quot; &lt;<a moz-do-not-s=
end=3D"true" href=3D"mailto:draft-ietf-behave-ipfix-nat-logging@tools.ietf.=
org">draft-ietf-behave-ipfix-nat-logging@tools.ietf.org</a>&gt;<br>
<span style=3D"font-weight:bold">Cc: </span>&quot;<a moz-do-not-send=3D"tru=
e" href=3D"mailto:behave@ietf.org">behave@ietf.org</a>&quot; &lt;<a moz-do-=
not-send=3D"true" href=3D"mailto:behave@ietf.org">behave@ietf.org</a>&gt;<b=
r>
<span style=3D"font-weight:bold">Subject: </span>AD Evaluation of draft-iet=
f-behave-ipfix-nat-logging-03<br>
<span style=3D"font-weight:bold">Resent-From: </span>&lt;<a moz-do-not-send=
=3D"true" href=3D"mailto:draft-alias-bounces@tools.ietf.org">draft-alias-bo=
unces@tools.ietf.org</a>&gt;<br>
<span style=3D"font-weight:bold">Resent-To: </span>&lt;<a moz-do-not-send=
=3D"true" href=3D"mailto:repenno@cisco.com">repenno@cisco.com</a>&gt;, Sent=
hil Sivakumar &lt;<a moz-do-not-send=3D"true" href=3D"mailto:ssenthil@cisco=
.com">ssenthil@cisco.com</a>&gt;<br>
<span style=3D"font-weight:bold">Resent-Date: </span>Thursday, May 1, 2014 =
4:26 PM<br>
</div>
<div><br>
</div>
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
              New,Courier,monospace">Dear draft-ietf-behave-ipfix-nat-loggi=
ng Authors,<br>
<br>
I've completed my AD evaluation for this draft. I found some things I'd lik=
e to see changed before proceeding, but most are editorial. Please take a l=
ook, and let me know what you think.<br>
<br>
My notes follow ... you should be able to find my questions and comments by=
 searching for &quot;SD:&quot;.<br>
<br>
Thanks,<br>
<br>
Spencer<br>
<br>
In the Abstract<br>
<br>
&nbsp;&nbsp; NAT devices are required to log events like creation and delet=
ion of<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^<br>
SD: Is this required, like, legally required, or ? Is it more like &quot;Op=
erators need NAT devices to log events ...&quot;?</font></div>
</div>
</span>
<div>[Senthil] : It is the later, the network operators require the NAT dev=
ices to be able to log events.</div>
</blockquote>
<br>
We don't usually include requirements language in the Abstract (that happen=
s later, which is fine in the document body).<br>
<br>
The longer I look at this, the more I think it's something like &quot;Opera=
tors expect NAT devices to log events&quot;.<br>
</div>
</div>
</span>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">
<div><span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
              New,Courier,monospace">&nbsp;&nbsp; translations and informat=
ion about the resources it is managing.&nbsp; The<br>
&nbsp;&nbsp; logs are required in many cases to identify an attacker or a h=
ost<br>
&nbsp;&nbsp; that was used to launch malicious attacks and/or for various o=
ther<br>
&nbsp;&nbsp; purposes of accounting.&nbsp; Since there is no standard way o=
f logging<br>
&nbsp;&nbsp; this information, different NAT devices behave differently and=
 hence<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^<br>
SD: Is this &quot;different NAT devices log this information differently&qu=
ot;? </font></div>
</div>
</span></div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">[Senthil] Correct, as the sentenc=
e says, &quot;Since there is no standard way=85&quot;, each NAT device logs=
 information in its own proprietary format.<font face=3D"Courier New,Courie=
r,monospace"><br>
</font></div>
<br>
I'm just trying to make sure the reader understands what you mean by &quot;=
behave differently&quot; - NAT devices also behave differently when NATting=
.&nbsp; I had to guess at the meaning. Maybe everyone else will understand?=
<br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
          New,Courier,monospace">&nbsp;&nbsp; it is difficult to expect a c=
onsistent behavior.&nbsp; The lack of a<br>
&nbsp;&nbsp; consistent way makes it difficult to write the collector appli=
cations<br>
&nbsp;&nbsp; that would receive this data and process it to present useful<=
br>
&nbsp;&nbsp; information.&nbsp; This document describes the information tha=
t is<br>
&nbsp;&nbsp; required to be logged by the NAT devices.<br>
&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^^^^ <br>
SD: Same as previous question - is this &quot;logged by&quot;?</font></div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div></div>
</span>
<div><br>
</div>
<div>[Senthil] If a NAT device is logging events, these are the requirement=
s that a NAT device should adhere to.</div>
</blockquote>
<br>
I know this seems tedious, but I'm not able to map what you provided as exp=
lanation onto the text you're explaining. What I'm seeing in the text is<br=
>
<br>
A NAT MUST log this information<br>
<br>
and what I'm seeing in your explanation is<br>
<br>
IF a NAT is is logging information, here's how the NAT SHOULD log informati=
on.<br>
<br>
I'm guessing that what you're saying is really &quot;this document describe=
s the information that logging NAT devices produce&quot;.
<br>
<br>
This doesn't matter yet (you're still in the abstract, which shouldn't be p=
roviding requirements anyway), but in the body of the document, it needs to=
 be clear.<br>
</div>
</div>
</span>
<div>
<div>[Senthil2] : How about I revise the text as:</div>
<div>
<pre style=3D"font-size: 1em; margin-top: 0px; margin-bottom: 0px; ">   Net=
work operators expect NAT devices to log events like creation and deletion =
of
   translations and information about the resources it is managing.  The
   logs are essential in many cases to identify an attacker or a host
   that was used to launch malicious attacks and/or for various other
   purposes of accounting.  Since there is no standard way of logging
   this information, different NAT devices log the information using propri=
etary formats</pre>
<pre style=3D"font-size: 1em; margin-top: 0px; margin-bottom: 0px; ">   and=
 hence it is difficult to expect a consistent behavior.  The lack of a
   consistent way to log the data makes it difficult to write the collector=
 applications
   that would receive this data and process it to present useful
   information.  This document describes the formats for logging of NAT eve=
nts.</pre>
</div>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
><span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
              New,Courier,monospace">2.&nbsp; Introduction<br>
<br>
&nbsp;&nbsp; The IPFIX Protocol [RFC5101bis] defines a generic push mechani=
sm for<br>
&nbsp;&nbsp; exporting information and events.&nbsp; The IPFIX Information =
Model<br>
&nbsp;&nbsp; [IPFIX-IANA] defines a set of standard Information Elements (I=
Es)<br>
&nbsp;&nbsp; which can be carried by the IPFIX protocol.&nbsp; This documen=
t details<br>
&nbsp;&nbsp; the IPFIX Information Elements(IEs) that are required for logg=
ing by<br>
&nbsp;&nbsp; a NAT device.&nbsp; The document will specify the format of th=
e IE's that<br>
&nbsp;&nbsp; are required to be logged by the NAT device and all the option=
al<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^<br>
SD: Now that we're in the document body, if this is required, shouldn't the=
re be a reference to where the requirements are stated?</font></div>
</div>
</span>
<div>[Senthil] This is the document that is specifying those requirements. =
Do you have any other suggestions of wording instead of &quot;required by&q=
uot;, would it be fine if I change the sentence from</div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">&quot;required to be logged&quot;=
 to &quot;SHOULD be logged&quot;?<font face=3D"Courier New,Courier,monospac=
e"><br>
</font></div>
</blockquote>
<br>
Sorry, my first set of comments was bogus. What triggered my comments was t=
he use of lower-case terms from RFC 2119 (see my explanation above).<br>
<br>
This could be &quot;are REQUIRED&quot; (the RFC 2119 requirements language =
you said you're using), or &quot;are required&quot; (if you change your par=
agraph about requirements language to say that case doesn't matter).<br>
<br>
But &quot;REQUIRED&quot; is &quot;MUST&quot;, so changing to &quot;SHOULD&q=
uot; would be a change in your intended meaning.</div>
</div>
</span>
<div><br>
</div>
<div>[Senthil2] I will change this to &quot;are REQUIRED&quot;.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
><br>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
              New,Courier,monospace">&nbsp;&nbsp; This document and [I-D.be=
have-syslog-nat-logging] are provided in<br>
&nbsp;&nbsp; order to standardize the events and parameters to be recorded,=
 using<br>
&nbsp;&nbsp; IPFIX [RFC5101bis] and SYSLOG [RFC5424]respectively.<br>
</font></div>
</div>
</span></blockquote>
<br>
I'm sorry I missed this question the first time. Is there a relationship wi=
th the MIB revision?</div>
</div>
</span>
<div><br>
</div>
<div>[Senthil2] Not directly, but there is some overlap of information that=
 can be obtained by using a MIB and the logging mechanisms.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
><span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
              New,Courier,monospace">3.&nbsp; Scope<br>
<br>
&nbsp;&nbsp; This document provides the information model to be used for lo=
gging<br>
&nbsp;&nbsp; the NAT devices including Carrier Grade NAT (CGN) events.&nbsp=
; This<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^<=
br>
SD: This sentence seems somewhat turned around - &quot;logging events&quot;=
, not &quot;logging the NAT devices&quot;.</font></div>
</div>
</span>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">[Senthil] Agree, I will change th=
is to &quot;logging the NAT events&quot;.
<font face=3D"Courier
          New,Courier,monospace"><br>
</font></div>
</blockquote>
<br>
Thanks.<br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
          New,Courier,monospace">&nbsp;&nbsp; document focuses exclusively =
on the specification of IPFIX IE's.<br>
&nbsp;&nbsp; This document does not provide guidance on the transport proto=
col<br>
&nbsp;&nbsp; like TCP, UDP or SCTP that is to be used to log NAT events.&nb=
sp; The log<br>
&nbsp;&nbsp; events SHOULD NOT be lost but the choice of the actual transpo=
rt<br>
&nbsp;&nbsp; protocol is beyond the scope of this document.<br>
<br>
SD: I'm not understanding why this last sentence is needed, especially with=
 a normative requirement for what you do when you are doing something outsi=
de the scope of the document ...</font></div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div></div>
</span>
<div>[Senthil] Are you objecting to the second part of the last sentence &q=
uot;the choice of actual transport=85&quot;, I think the requirement is tha=
t the LOG events should not be lost is valid.</div>
</blockquote>
<br>
I'm sorry, my question wasn't clear. What I intended to say was that I was =
confused because the text said &quot;not providing guidance on the choice o=
f a transport protocol&quot;, but then provided a requirement about the imp=
lications of that choice (using a SHOULD).<br>
<br>
So let me try to be clearer. I think what you're saying is <br>
<br>
- you can use any transport protocol, but you SHOULDn't lose anything<br>
<br>
I'm thinking this may be underspecified, although I don't know what IPFIX u=
sually expects from transport protocols, so please be patient.<br>
<br>
First, I'm confused by the SHOULD with no qualification. When is it OK to l=
ose LOG events?</div>
</div>
</span>
<div>[Senthil] Ideally you should never lose the logs, but if the box crash=
es or an irrecoverable error happens.&nbsp;</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<br>
Second, you're not giving guidance on selecting a transport protocol, but y=
ou are giving guidance about expecting a reliable data channel, whether MUS=
T be reliable or SHOULD be reliable. Are there other transport characterist=
ics that you expect? For instance,
 is in-order delivery assumed? Is duplicate detection by IPFIX assumed (if =
a log arrives twice, does IPFIX notice)?</div>
</div>
</span>
<div>[Senthil2] There is no need for in-order delivery, the collector shoul=
d be able to detect two identical events at the exact same time stamp as du=
plicates. The only transport characteristic required is the reliability.&nb=
sp;</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
Third, are IPFIX implementations so transport protocol-agnostic that if my =
NAT device decides to to send logs using SCTP with partial reliability, I s=
hould expect that to work with any collector that implements this specifica=
tion?</div>
</div>
</span>
<div>[Senthil2] One of the reasons for not giving the guidance is that IPFI=
X was initially SCTP only but in the latest RFC 7011, IPFIX can be transpor=
ted using TCP/UDP/SCTP and others. As long as both the devices are using IP=
FIX,</div>
<div>and the receiving collector is able to parse and understand SCTP, it s=
hould work. There is a little bit of configuration required, I would think,=
 to tell the NAT device on what protocol and port to use, to specify where =
the collector is</div>
<div>listening.&nbsp;</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<br>
It happens that I co-chaired MEDIACTRL when the specification said &quot;TC=
P or SCTP&quot;, and got feedback during AD evaluation that if we didn't pi=
ck a mandatory to implement transport protocol, that wouldn't guarantee int=
eroperation between two standard-conforming
 devices.</div>
</div>
</span>
<div><br>
</div>
<div>[Senthil2] Ok, I don=92t know if in this case, I could pick a transpor=
t protocol to use with IPFIX, since IPFIX allows that flexibility and NAT l=
ogs are transported over IPFIX, people would expect that we support all the=
 transport protocols that IPFIX supports.
 Let me know if you have better suggestions on what the guidance should be.=
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
><span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
              New,Courier,monospace"><br>
&nbsp;&nbsp; The existing IANA IPFIX IEs registry [IPFIX-IANA] already has<=
br>
&nbsp;&nbsp; assignments for many NAT logging events.&nbsp; For convenience=
, this<br>
&nbsp;&nbsp; document uses those same IEs.&nbsp; However, as stated earlier=
, this<br>
&nbsp;&nbsp; document is not defining IPFIX or NetFlow v9 as the framework =
for<br>
&nbsp;&nbsp; logging.&nbsp; Rather, the information contained in these elem=
ents is<br>
<br>
SD: I got lost on &quot;these elements&quot; - is that &quot;the elements i=
n the existing registry&quot;</font></div>
</div>
</span>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">[Senthil] Yes. How about &quot;Ra=
ther, the information elements as defined in the IPFIX-IANA registry is wit=
hin the scope of this document&quot;?<font face=3D"Courier New,Courier,mono=
space"><br>
</font></div>
</blockquote>
<br>
<font face=3D"Courier New,Courier,monospace">I think that's &quot;are withi=
n&quot;, but yes, that works. Thanks.<br>
<br>
</font>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
          New,Courier,monospace">&nbsp;&nbsp; within the scope of this docu=
ment.<br>
<br>
&nbsp;&nbsp; This document assumes that the NAT device will use the existin=
g IPFIX<br>
&nbsp;&nbsp; framework to send the log events to the collector.&nbsp; This =
would mean<br>
&nbsp;&nbsp; that the NAT device will specify the template that it is going=
 to use<br>
&nbsp;&nbsp; for each of the events.&nbsp; The templates can be of varying =
length and<br>
&nbsp;&nbsp; there could be multiple templates that a NAT device could use =
to log<br>
&nbsp;&nbsp; the events.<br>
<br>
&nbsp;&nbsp; The implementation details of the collector application is bey=
ond the<br>
&nbsp;&nbsp; scope of this document.<br>
<br>
&nbsp;&nbsp; The optimization of logging the NAT events are left to the<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^<br>
&nbsp;&nbsp; implementation and are beyond the scope of this document.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^<br>
SD: It's a nit, but those &quot;are&quot;s should be &quot;is&quot;s.</font=
></div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div></div>
</span>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">[Senthil] Ok.<font face=3D"Courie=
r New,Courier,monospace"><br>
</font></div>
</blockquote>
<br>
Thanks.<br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
          New,Courier,monospace">4.&nbsp; Applicability<br>
<br>
&nbsp;&nbsp; NAT logging based on IPFIX uses binary encoding and hence is v=
ery<br>
&nbsp;&nbsp; efficient.&nbsp; IPFIX based logging is recommended for enviro=
nments where<br>
&nbsp;&nbsp; a high volume of logging is required, for example, where per-f=
low<br>
&nbsp;&nbsp; logging is needed.&nbsp; However, IPFIX based logging requires=
 a collector<br>
&nbsp;&nbsp; that processes the binary data and requires a network manageme=
nt<br>
&nbsp;&nbsp; application that converts this binary data to a human readable=
<br>
&nbsp;&nbsp; format.<br>
<br>
5.&nbsp; Event based logging<br>
<br>
&nbsp;&nbsp; An event in a NAT device can be viewed as a happening as it re=
lates<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^<br>
SD: Is this &quot;a state transition&quot;? I found &quot;a happening&quot;=
 somewhat odd.</font></div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div></div>
</span>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">[Senthil] Yes, I can rephrase thi=
s as &quot;viewed as a state transition as it relates to&quot; or &quot;vie=
wed as an action as it relates to&quot;, if that is ok.<font face=3D"Courie=
r New,Courier,monospace"><br>
</font></div>
</blockquote>
<br>
If &quot;a state transition&quot; is correct, I'd prefer that (if it's corr=
ect :-) ).<br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
          New,Courier,monospace">&nbsp;&nbsp; to the management of NAT reso=
urces.&nbsp; The creation and deletion of NAT<br>
&nbsp;&nbsp; sessions and bindings are examples of events as it results in =
the<br>
&nbsp;&nbsp; resources (addresses and ports) being allocated or freed.&nbsp=
; The events<br>
&nbsp;&nbsp; can happen either through the processing of data packets flowi=
ng<br>
&nbsp;&nbsp; through the NAT device or through an external entity installin=
g<br>
&nbsp;&nbsp; policies on the NAT router or as a result of an asynchronous e=
vent<br>
&nbsp;&nbsp; like a timer.&nbsp; The list of events are provided in Section=
 4.1.&nbsp; Each<br>
&nbsp;&nbsp; of these events SHOULD be logged, unless they are administrati=
vely<br>
&nbsp;&nbsp; prohibited.&nbsp; A NAT device MAY log these events to multipl=
e collectors<br>
&nbsp;&nbsp; if redundancy is required.&nbsp; The network administrator wil=
l specify<br>
&nbsp;&nbsp; the collectors to which the log records are to be sent.<br>
<br>
&nbsp;&nbsp; A collector may receive NAT events from multiple CGN devices a=
nd<br>
&nbsp;&nbsp; should be able to distinguish between the devices.&nbsp; Each =
CGN device<br>
&nbsp;&nbsp; ^^^^^^<br>
SD: I'm not sure why this isn't a SHOULD, or even a MUST.<br>
<br>
&nbsp;&nbsp; should have a unique source ID to identify themselves.&nbsp; T=
he source ID<br>
&nbsp;&nbsp; ^^^^^^<br>
SD: Again, I'm not sure why this isn't a SHOULD, or even a MUST.</font></di=
v>
<span id=3D"OLK_SRC_BODY_SECTION">
<div></div>
</span>
<div><br>
</div>
<div>[Senthil] Well, this is NOT a statement for a NAT device, instead it i=
s a collector that some application writer will&nbsp;</div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">develop. <font face=3D"Courier Ne=
w,Courier,monospace">
<br>
</font></div>
</blockquote>
<br>
Don't you think you can levy requirements about that on the collector? I do=
n't understand.
<br>
</div>
</div>
</span>
<div>[Senthil2] This document was written for how the NAT devices should se=
nd their logs and their formats. I am not sure if I am opening a can of wor=
ms, by</div>
<div>Starting to specify what the collector should do as part of this docum=
ent.&nbsp;</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
But beyond that, what I THINK the text is saying, is that multiple CGN devi=
ces can (&quot;may&quot;) send to a single collector,
</div>
</div>
</span>
<div>[Senthil2] Yes.</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">that none of the CDN devices have=
 to have a unique source ID to identify themselves (&quot;should&quot;, but=
 not &quot;must&quot;), &nbsp;</div>
</div>
</span>
<div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;^^^^^</div>
<div>[Senthil2] No, that is not what the text is saying . In fact it says t=
he opposite, &nbsp;</div>
<div>
<pre class=3D"newpage" style=3D"font-size: 1em; margin-top: 0px; margin-bot=
tom: 0px; page-break-before: always; ">&quot;Each CGN device <span style=3D=
"font-size: 1em; font-family: Calibri, sans-serif; ">should have a unique s=
ource ID to identify themselves.&quot;</span></pre>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"></div>
</div>
</span>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">and that the collector is still e=
xpected to be able to distinguish among logs coming from multiple CGNs (&qu=
ot;should&quot;).</div>
</div>
</span>
<div><br>
</div>
<div>[Senthil2] Yes, the collector should be able to distinguish the record=
s coming in from distinct sources. This is a generic IPFIX requirement,</di=
v>
<div>That a collector is able to handle multiple sources. Maybe I should re=
move this text on the collector as it seems to cause more confusion?</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<br>
Am I misreading this?<br>
<br>
If not, do you think that works?</div>
</div>
</span>
<div><br>
</div>
<div>[Senthil2] Please see above, let me know if I misunderstood what you w=
ere asking.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
          New,Courier,monospace">&nbsp;&nbsp; is part of the IPFIX template=
 and data exchange.<br>
<br>
&nbsp;&nbsp; Prior to logging any events, the NAT device MUST send the temp=
late of<br>
&nbsp;&nbsp; the record to the collector to advertise the format of the dat=
a<br>
&nbsp;&nbsp; record that it is using to send the events.&nbsp; The template=
s can be<br>
&nbsp;&nbsp; exchanged as frequently as required given the reliability of t=
he<br>
&nbsp;&nbsp; connection.&nbsp; There SHOULD be a configurable timer for con=
trolling the<br>
&nbsp;&nbsp; template refresh.&nbsp; NAT device SHOULD combine as many even=
ts as<br>
&nbsp;&nbsp; possible in a single packet to effectively utilize the network=
<br>
&nbsp;&nbsp; bandwidth.<br>
<br>
5.1.&nbsp; Logging of destination information<br>
<br>
&nbsp;&nbsp; Logging of destination information in a NAT event has been dis=
cussed<br>
&nbsp;&nbsp; in [RFC6302] and [RFC6888].&nbsp; Logging of destination infor=
mation<br>
&nbsp;&nbsp; increases the size of each record and increases the need for s=
torage<br>
&nbsp;&nbsp; considerably.&nbsp; It increases the number of log events gene=
rated<br>
&nbsp;&nbsp; because when the same user connects to a different destination=
, it<br>
&nbsp;&nbsp; results in a log record per destination address.&nbsp; Logging=
 of<br>
&nbsp;&nbsp; destination information also results in the loss of privacy an=
d hence<br>
&nbsp;&nbsp; should be done with caution.&nbsp; However, this draft provide=
s the<br>
&nbsp;&nbsp; necessary fields to log the destination information in cases w=
here<br>
&nbsp;&nbsp; they are required to be logged.<br>
<br>
5.2.&nbsp; Information Elements<br>
<br>
&nbsp;&nbsp; The templates could contain a subset of the Information Elemen=
ts(IEs)<br>
&nbsp;&nbsp; shown in Table 1 depending upon the event being logged.&nbsp; =
For example<br>
&nbsp;&nbsp; a NAT44 session creation template record will contain,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^<br>
SD: Is this the only possible NAT44 template? If so, fine, but if not, perh=
aps &quot;could contain&quot;, or &quot;typically contains&quot;?</font></d=
iv>
<span id=3D"OLK_SRC_BODY_SECTION">
<div></div>
</span>
<div><br>
</div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">[Senthil] Yes, this is all the in=
formation that a NAT44 need to export as it is the least common denominator=
.<font face=3D"Courier New,Courier,monospace"><br>
</font></div>
</blockquote>
<br>
My question is whether any other IEs might be added in the future, I think.=
 If not, &quot;will&quot; is OK, but &quot;MUST&quot; would be clearer.</di=
v>
</div>
</span>
<div><br>
</div>
<div>[Senthil2] I think this is the base information required, but difficul=
t to predict what will be added in the future, so I am going to leave it as=
 is, unless you have objection.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
          New,Courier,monospace">&nbsp;&nbsp; {sourceIPv4Adress, postNATSou=
rceIPv4Address, destinationIpv4Address,<br>
&nbsp;&nbsp; postNATDestinationIPv4Address, sourceTransportPort,<br>
&nbsp;&nbsp; postNAPTSourceTransportPort, destinationTransportPort,<br>
&nbsp;&nbsp; postNAPTDestTransportPort, internalAddressRealm, natEvent, tim=
eStamp}<br>
<br>
&nbsp;&nbsp; An example of the actual event data record is shown below - in=
 a<br>
&nbsp;&nbsp; readable form<br>
<br>
&nbsp;&nbsp; {192.168.16.1, 201.1.1.100, 207.85.231.104, 207.85.231.104, 14=
800,<br>
&nbsp;&nbsp; 1024, 80, 80, 0, 1, 09:20:10:789}<br>
<br>
&nbsp;&nbsp; A single NAT device could be exporting multiple templates and =
the<br>
&nbsp;&nbsp; collector should support receiving multiple templates from the=
 same<br>
&nbsp;&nbsp; source.observationTimeMilliseconds<br>
<br>
&nbsp;&nbsp; The following is the table of all the IE's that a CGN device w=
ould<br>
&nbsp;&nbsp; need to export the events.&nbsp; The formats of the IE's and t=
he IPFIX IDs<br>
&nbsp;&nbsp; are listed below.<br>
<br>
SD: I noticed that some IEs below have a name that matches <a moz-do-not-se=
nd=3D"true" class=3D"moz-txt-link-freetext" href=3D"http://www.iana.org/ass=
ignments/ipfix/ipfix.xhtml#ipfix-information-elements">
http://www.iana.org/assignments/ipfix/ipfix.xhtml#ipfix-information-element=
s</a> for the same IPFIX ID number, but others do not (&quot;timeStamp&quot=
; here doesn't match &quot;observationTimeMilliseconds&quot;, but both are =
IPFIX ID 323, aren't they?) Is there a reason to use
 names that don't match the IANA registry?</font></div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div></div>
</span>
<div><br>
</div>
<div>[Senthil] Good question, in case of timeStamp, I was looking for somet=
hing that already existed in the IPFIX registry rather than asking for a ne=
w one. However, the terminology of &quot;observationTimeMilliseconds&quot; =
is not the terminology that we use in the
 NAT drafts/rfc's. So I am open to suggestions here. I can clarify in the d=
escription that is called observationTimeMilliSeconds&quot;. The other fiel=
d is internalAddressRealm and externalAddresRealm, this is the terminology =
that we used in NAT MIB, syslog and other
 documents. However, when we defined the IPFIX IE, we didn=92t stick to the=
 same terminology, so I don=92t know if I can go and ask the IPFIX IANA to =
change the name. Again I am open to suggestions, the dillema is whether I s=
hould stick to the existing IPFIX IANA
 terminology or the behave documents terminology.</div>
</blockquote>
<br>
I'm way out of my depth on this one (sorry!).<br>
<br>
Fortunately, the next stop for an AD-sponsored IPFIX specification is the I=
PFIX review team. Could you just add a note pointing this question out, and=
 asking if they have any suggestions?</div>
</div>
</span>
<div><br>
</div>
<div>[Senthil2] I will send out an email to the IPFIX mailing list and to t=
he people who reviewed it from the IPFIX WG.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
><span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
              New,Courier,monospace">&nbsp;&nbsp; &#43;--------------------=
--------------&#43;--------&#43;-------&#43;---------------&#43;<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp; |&nbsp;&nbsp; Size |&nbsp; IANA |&nbsp; Description&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | (bits) | I=
PFIX |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; ID |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; &#43;----------------------------------&#43;--------&#43;-----=
--&#43;---------------&#43;<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp; 323 |&nbsp; System =
Time&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; when the&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp; event&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; occured.&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natIns=
tanceId&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; TBD |&nbsp; NAT Instance |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp; Identifier&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; vlanID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp=
; 58 |&nbsp;&nbsp; VLAN ID in&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; case of&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; overlapping&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; networks&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 234 |&nbsp;&nbsp; VRF ID in&nbsp;&=
nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; case of&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; overlapping&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; networks&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv4Address&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 3=
2 |&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp; Source IPv4&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; Address&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv4Address&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 225 |&nbsp;&nbsp; T=
ranslated&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; Source IPv4&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; Address&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; protocolIdentifier=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
8 |&nbsp;&nbsp;&nbsp;&nbsp; 4 |&nbsp;&nbsp; Transport&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; protocol&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceTransportPort&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&=
nbsp;&nbsp;&nbsp; 7 |&nbsp; Source Port&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp; postNAPTsourceTransportPort&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp; 227 |&nbsp;&nbsp; Translated&nbsp;=
 |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; Source port&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationIPv4Address&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; 12 =
|&nbsp; Destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; IPv4 Address |<br>
&nbsp;&nbsp; |&nbsp; postNATDestinationIPv4Address&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 226 |&nbsp;&nbsp; Translated&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp; IPv4&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; address&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; destinationTransportPort&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; 11 |&nbsp; De=
stination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp; port&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; | postNAPTdestinationTransportPort |&nbsp;&nbsp;&nbsp;&nbsp; 1=
6 |&nbsp;&nbsp; 228 |&nbsp;&nbsp; Translated&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; Destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp; port&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv6Address&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 2=
7 |&nbsp;&nbsp; 128 |&nbsp; Source IPv6&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; address&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationIPv6Address&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp; 28 |&nbs=
p; Destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; IPv6 address |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv6Address&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp; 281 |&nbsp;&nbsp; Transl=
ated&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; source IPv6&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp; addresss&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp; postNATDestinationIPv6Address&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp; 128 |&nbsp;&nbsp; 282 |&nbsp;&nbsp; Translated&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; Destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p; IPv6 address |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; internalAddressRealm&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&=
nbsp; 229 |&nbsp;&nbsp;&nbsp;&nbsp; Source&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Add=
ress Realm |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; externalAddressRealm&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&=
nbsp; TBD |&nbsp; Destination&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Add=
ress Realm |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp; 230 | Typ=
e of Event |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; portRa=
ngeStart&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp; 16 |&nbsp;&nbsp; 361 |&nbsp;&nbsp; Allocated&nbsp;&nbsp; |<br=
>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp; port block&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp; start&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
portRangeEnd&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp; 362 |&nbsp;&nbsp; Allocated&nbsp;&=
nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp; Port block&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp; end&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; natPoolID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; 283 |&nbsp;&nbsp;&n=
bsp; NAT pool&nbsp;&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp; Identifier&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natLim=
itEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp; TBD |&nbsp; Limit event&nbsp; |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp; identifier&nbsp; |<br>
&nbsp;&nbsp; &#43;----------------------------------&#43;--------&#43;-----=
--&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 1: Template forma=
t Table<br>
<br>
5.3.&nbsp; Definition of NAT Events<br>
<br>
&nbsp;&nbsp; The following are the list of NAT events and the proposed even=
t<br>
&nbsp;&nbsp; values.&nbsp; The list can be expanded in the future as necess=
ary.&nbsp; The<br>
&nbsp;&nbsp; data record will have the corresponding natEvent value to iden=
tify<br>
&nbsp;&nbsp; the event that is being logged.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------&#43;-----=
---&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p; Event Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Values |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------&#43;-----=
---&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT44 Session create&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT44 Session delete&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | NAT Addresses exhausted&nbsp; |&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp; 3 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT64 Session create&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT64 Session delete&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 5 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT44 BIB creat=
e&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 6 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT44 BIB delet=
e&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 7 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT64 BIB creat=
e&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; NAT64 BIB delet=
e&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 9 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; NAT ports exhausted&nbsp;&n=
bsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 10 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Quota exc=
eeded&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 11 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Address binding create&nbsp; |&nb=
sp;&nbsp;&nbsp;&nbsp; 12 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Address binding delete&nbsp; |&nb=
sp;&nbsp;&nbsp;&nbsp; 13 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; Port block allocation&nbsp;&nbsp;=
 |&nbsp;&nbsp;&nbsp;&nbsp; 14 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Port block de-allocation |&nbsp;&nbsp;&=
nbsp;&nbsp; 15 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; Threshold reached&nbs=
p;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; 16 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------&#43;-----=
---&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 2: NA=
T Event ID table<br>
<br>
5.4.&nbsp; Quota exceeded Event types<br>
<br>
&nbsp;&nbsp; The following table shows the sub event types for the Quota ex=
ceeded<br>
&nbsp;&nbsp; or limits reached event.&nbsp; The events that can be reported=
 are the<br>
&nbsp;&nbsp; Maximum session entries limit reached, Maximum BIB entries lim=
it<br>
&nbsp;&nbsp; reached, Maximum session/BIB entries per user limit reached an=
d<br>
&nbsp;&nbsp; maximum subscribers or hosts limit reached.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---=
------------------------------------&#43;--------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Quota Exceeded Event Name&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp; | Values |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---=
------------------------------------&#43;--------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Maximum Session entries&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Maximum BIB entries&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; 2 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Maximum entries per user&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; =
Maximum active hosts or subscribers&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4=
 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; =
Maximum fragments pending reassembly |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 5 |<br=
>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---=
------------------------------------&#43;--------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 3: Quota Exceeded event table=
<br>
<br>
5.5.&nbsp; Threshold reached Event types<br>
<br>
&nbsp;&nbsp; The following table shows the sub event types for the threshol=
d<br>
&nbsp;&nbsp; reached event.&nbsp; The administrator can configure the thres=
holds and<br>
&nbsp;&nbsp; whenever the threshold is reached or exceeded, the correspondi=
ng<br>
&nbsp;&nbsp; events are generated.<br>
<br>
&nbsp;&nbsp; The address pool high threshold event will be reported when th=
e<br>
&nbsp;&nbsp; address pool reaches a high water mark as defined by the opera=
tor.<br>
&nbsp;&nbsp; This will sever as an indication that the operator might have =
to add<br>
&nbsp;&nbsp; more addresses to the pool or an indication that the subsequen=
t users<br>
&nbsp;&nbsp; may be denied NAT translation mappings.<br>
<br>
&nbsp;&nbsp; The address and port mapping high threshold event is generated=
, when<br>
&nbsp;&nbsp; the number of ports in the configured address pool has reached=
 a<br>
&nbsp;&nbsp; configured threshold.<br>
<br>
&nbsp;&nbsp; The per-user address and port mapping high threshold is genera=
ted<br>
&nbsp;&nbsp; when a single user uses more address and port mapping than a<b=
r>
&nbsp;&nbsp; configured threshold.<br>
<br>
&nbsp;&nbsp; &#43;---------------------------------------------------------=
&#43;--------&#43;<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; Threshold Exceeded Event Name&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Values |<br>
&nbsp;&nbsp; &#43;---------------------------------------------------------=
&#43;--------&#43;<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; Address pool high threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1 |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; Address pool low threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2 |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Address and port mapping high =
threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p; 3 |<br>
&nbsp;&nbsp; |&nbsp; Address and port mapping per user high threshold event=
 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4 |<br>
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Global Address mapping h=
igh threshold event&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; 5 |<br>
&nbsp;&nbsp; &#43;---------------------------------------------------------=
&#43;--------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 4: Threshold even=
t table<br>
<br>
5.6.&nbsp; Templates for NAT Events<br>
<br>
&nbsp;&nbsp; The following is the template of events that will have to logg=
ed.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^=
^^<br>
<br>
SD: I think this is a nit, but the sentence is garbled. &quot;will be logge=
d&quot;?<br>
<br>
&nbsp;&nbsp; The events below are identified at the time of this writing bu=
t the<br>
&nbsp;&nbsp; events are expandable.&nbsp; Depending on the implementation a=
nd<br>
&nbsp;&nbsp; ^^^^^^^^^^^^^^^^^^^^^<br>
SD: this is a nit, but &quot;set of events is extensible&quot;, I think.</f=
ont></div>
</div>
</span>
<div><br>
</div>
<div>[Senthil] Agree. (to both comments).</div>
</blockquote>
<br>
Thanks,<br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
><span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
              New,Courier,monospace">&nbsp;&nbsp; configuration various IE'=
s specified can be included or ignored.<br>
<br>
5.6.1.&nbsp; NAT44 create and delete session events<br>
<br>
&nbsp;&nbsp; These events will be generated when a NAT44 session is created=
 or<br>
&nbsp;&nbsp; deleted.&nbsp; The template will be the same, the natEvent wil=
l indicate<br>
&nbsp;&nbsp; whether it is a create or a delete event.&nbsp; The following =
is a<br>
&nbsp;&nbsp; template of the event.<br>
<br>
&nbsp;&nbsp; The destination address and port information is optional as re=
quired<br>
&nbsp;&nbsp; by [RFC6888].&nbsp; However, when the destination information =
is<br>
&nbsp;&nbsp; suppressed, the session log event contains the same informatio=
n as<br>
&nbsp;&nbsp; the BIB event.&nbsp; In such cases, the NAT device SHOULD NOT =
send both<br>
&nbsp;&nbsp; BIB and session events.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbs=
p;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; vlanID=
/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
sourceIPv4Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&n=
bsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv4A=
ddress&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&n=
bsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; source=
TransportPort&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;=
&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNAPTsourceTransportPort&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 =
|&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationI=
Pv4Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<b=
r>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; postNATDestinationIPv4Address&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nb=
sp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; destinationTranspo=
rtPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTdestinationTransportPort |&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp;=
 No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; intern=
alAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; extern=
alAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; Table 5: NAT44 Session delete/create template<br>
<br>
5.6.2.&nbsp; NAT64 create and delete session events<br>
<br>
&nbsp;&nbsp; These events will be generated when a NAT64 session is created=
 or<br>
&nbsp;&nbsp; deleted.&nbsp; The following is a template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbs=
p;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; vlanID=
/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
sourceIPv6Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; postNATSourceIPv4A=
ddress&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&n=
bsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; source=
TransportPort&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;=
&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNAPTsourceTransportPort&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 =
|&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; destinationI=
Pv6Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; postNATDestinationIPv4Address&nbsp;&=
nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nb=
sp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; destinationTranspo=
rtPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTdestinationTransportPort |&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp;=
 No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; intern=
alAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; extern=
alAddressRealm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&=
nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;----------------------------------&#43;=
-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 6:=
 NAT64 session create/delete event template<br>
<br>
5.6.3.&nbsp; NAT44 BIB create and delete events<br>
<br>
&nbsp;&nbsp; These events will be generated when a NAT44 Bind entry is crea=
ted or<br>
&nbsp;&nbsp; deleted.&nbsp; The following is a template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbs=
p;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
vlanID/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; sourceIPv4Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&n=
bsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNATSourc=
eIPv4Address&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nb=
sp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
sourceTransportPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTsourceTransportP=
ort |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp=
;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
internalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
externalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Table 7: NAT44 BIB create/delete event template<br>
<br>
5.6.4.&nbsp; NAT64 BIB create and delete events<br>
<br>
&nbsp;&nbsp; These events will be generated when a NAT64 Bind entry is crea=
ted or<br>
&nbsp;&nbsp; deleted.&nbsp; The following is a template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp; | Size (bits) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbs=
p;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
vlanID/ingressVRFID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; sourceIPv6Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; postNATSourc=
eIPv4Address&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; protocolIdentifier&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nb=
sp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
sourceTransportPort&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNAPTsourceTransportP=
ort |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp=
;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
internalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; =
externalAddressRealm&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------------=
--------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Table 8: NAT64 BIB create/delete event template<br>
<br>
5.6.5.&nbsp; Addresses Exhausted event<br>
<br>
&nbsp;&nbsp; This event will be generated when a NAT device runs out of glo=
bal<br>
&nbsp;&nbsp; IPv4 addresses in a given pool of addresses.&nbsp; Typically, =
this event<br>
&nbsp;&nbsp; would mean that the NAT device wont be able to create any new<=
br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ^^^^<br>
SD: &quot;won't&quot;</font></div>
</div>
</span>
<div><br>
</div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000">[Senthil] Ok.<font face=3D"Courie=
r New,Courier,monospace"><br>
</font></div>
</blockquote>
<br>
Thanks,<br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
          New,Courier,monospace"><br>
&nbsp;&nbsp; translations until some addresses/ports are freed.&nbsp; This =
event SHOULD<br>
&nbsp;&nbsp; be rate limited as many packets hitting the device at the same=
 time<br>
&nbsp;&nbsp; will trigger a burst of addresses exhausted events.<br>
<br>
&nbsp;&nbsp; The following is a template of the event.&nbsp; Note that eith=
er the NAT<br>
&nbsp;&nbsp; pool name or the nat pool identifier should be logged, but not=
 both.<br>
<br>
SD: I lack understanding, but I didn't see anything that looked like a NAT =
pool name in the template. Did I miss something?</font></div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div></div>
</span>
<div><br>
</div>
<div>[Senthil] We decided not to use a string like a pool name instead use =
a poolID, which is a unique identifier for each pool name. The reason being=
 that the logs could become fairly large&nbsp;</div>
<div>If we have to carry the names and some of the NAT engines implement th=
is in the hardware that lacks the string processing capability.</div>
</blockquote>
<br>
OK, that helps. I'm understanding that a different template might have incl=
uded a pool name, but not a poolID, is that right?<br>
<br>
I'm somewhat uneasy about the &quot;either should be logged, but not both&q=
uot; text.</div>
</div>
</span>
<div><br>
</div>
<div>[Senthil2] That text is not relevant anymore and should be removed, th=
ere was a time we had both poolName &amp; poolID.&nbsp;</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
<br>
Same question as usual - is this an RFC 2119 SHOULD that helps with interop=
eration, or is this about an implementation choice?<br>
<br>
If it's an RFC 2119 SHOULD, robust collectors will need to do something if =
a log arrives with both a pool name and a poolID. If it's a MUST, a collect=
or wouldn't accept the log (however the collector would decide to do that).=
</div>
</div>
</span>
<div><br>
</div>
<div>[Senthil2] As you see in the below template, if the mandatory field is=
 Yes, then the NAT device MUST log it. If the field is not mandatory, then =
the nat device can choose to send it or not. But the actual template will t=
hat the device sends indicates what
 the device is sending and the data set will correspond to the template, an=
d the collector will correlate the template and the data sets.</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><br>
If it's not an RFC 2119 SHOULD, but just implementation guidance, the expla=
nation you provided would be more helpful (something like &quot;could inclu=
de a pool name, but some NAT engines are implemented in hardware that lacks=
 string processing capability, and these
 are permitted to substitute a poolID. There's no reason to provide both a =
pool name and a poolID&quot;).<br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
><span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
              New,Courier,monospace">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------&#=
43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp; Field Name&nbsp; | Size (bits) | Mandatory |<=
br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; &#43;---------------&#43;-------------&#43;-----------&#43;=
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp; timeStamp&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbs=
p; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; | natInstanceID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;=
&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; |&nbsp;&nbsp; natPoolID&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbs=
p; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; &#43;---------------&#43;-------------&#43;-----------&#43;=
<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; Table 9: Address Exhausted event template<br>
<br>
5.6.6.&nbsp; Ports Exhausted event<br>
<br>
&nbsp;&nbsp; This event will be generated when a NAT device runs out of por=
ts for<br>
&nbsp;&nbsp; a global IPv4 address.&nbsp; Port exhaustion shall be reported=
 per<br>
&nbsp;&nbsp; protocol (UDP, TCP etc).&nbsp; This event SHOULD be rate limit=
ed as many<br>
&nbsp;&nbsp; packets hitting the device at the same time will trigger a bur=
st of<br>
&nbsp;&nbsp; port exhausted events.<br>
<br>
&nbsp;&nbsp; The following is a template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-----------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
; | Size (bits) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-----------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&n=
bsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&=
nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8=
 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | postNATSourceIPv4A=
ddress |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&n=
bsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; =
protocolIdentifier&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-----------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; Table 10: Ports Exhausted event template<br>
<br>
5.6.7.&nbsp; Quota exceeded events<br>
<br>
&nbsp;&nbsp; This event will be generated when a NAT device cannot allocate=
<br>
&nbsp;&nbsp; resources as a result of an administratively defined policy.&n=
bsp; The<br>
&nbsp;&nbsp; quota exceeded event templates are described below<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; ^<br>
SD: missing period</font></div>
</div>
</span>
<div>[Senthil] Ok.</div>
</blockquote>
<br>
Thanks,<br>
<br>
<blockquote cite=3D"mid:CF89605B.1009FB%25ssenthil@cisco.com" type=3D"cite"=
><span id=3D"OLK_SRC_BODY_SECTION">
<div>
<div bgcolor=3D"#FFFFFF" text=3D"#000000"><font face=3D"Courier
              New,Courier,monospace">5.6.7.1.&nbsp; Maximum session entries=
 exceeded<br>
<br>
&nbsp;&nbsp; The maximum session entries exceeded is generated when the<br>
&nbsp;&nbsp; administratively configured limit is reached.&nbsp; The follow=
ing is the<br>
&nbsp;&nbsp; template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp; | Size (bits) | Mandat=
ory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbs=
p;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natInstanceID&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes=
&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natLimitEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; | configuredLimit |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ta=
ble 11: Session Entries Exceeded event template<br>
<br>
5.6.7.2.&nbsp; Maximum BIB entries exceeded<br>
<br>
&nbsp;&nbsp; The maximum BIB entries exceeded is generated when the<br>
&nbsp;&nbsp; administratively configured limit is reached.&nbsp; The follow=
ing is the<br>
&nbsp;&nbsp; template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp; | Size (bits) | Mandat=
ory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbs=
p;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natInstanceID&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes=
&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natLimitEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; | configuredLimit |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; Table 12: BIB Entries Exceeded event template<br>
<br>
5.6.7.3.&nbsp; Maximum entries per user exceeded<br>
<br>
&nbsp;&nbsp; This event is generated when a single user reaches the<br>
&nbsp;&nbsp; administratively configured limit.&nbsp; The following is the =
template of<br>
&nbsp;&nbsp; the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) |&nbsp;&=
nbsp; Mandatory&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp; natInstanceID&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp; natLimitEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; =
configuredLimit&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | vlanID/ingre=
ssVRFID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; source=
IPv4 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 | Y=
es for NAT44 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; source=
IPv6 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 | Yes fo=
r NAT64 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 13=
: Per-user Entries Exceeded event template<br>
<br>
5.6.7.4.&nbsp; Maximum active host or subscribers exceeded<br>
<br>
&nbsp;&nbsp; This event is generated when the number of allowed hosts or<br=
>
&nbsp;&nbsp; subscribers reaches the administratively configured limit.&nbs=
p; The<br>
&nbsp;&nbsp; following is the template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp; | Size (bits) | Mandat=
ory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbs=
p;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natInstanceID&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp; Yes=
&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; |&nbsp; natLimitEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; | configuredLimit |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &#43;-----------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 14: Maximum hosts/subscrib=
ers Exceeded event template<br>
<br>
5.6.7.5.&nbsp; Maximum fragments pending reassembly exceeded<br>
<br>
&nbsp;&nbsp; This event is generated when the number of fragments pending<b=
r>
&nbsp;&nbsp; reassembly reaches the administratively configured limit.&nbsp=
; The<br>
&nbsp;&nbsp; following is the template of the event.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) |&nbsp;&=
nbsp; Mandatory&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; =
natInstanceID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp; =
natLimitEvent&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; config=
uredLimit&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | internalAddressRea=
lm |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | vlanID/ingressVRFI=
D&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; sourceIPv4 a=
ddress&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 | Y=
es for NAT44 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; sourceIPv6 a=
ddress&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 | Yes fo=
r NAT64 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------------=
-------&#43;-------------&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 15: Maximum fragments pending re=
assembly Exceeded event<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; template<br>
<br>
5.6.8.&nbsp; Threshold reached events<br>
<br>
&nbsp;&nbsp; This event will be generated when a NAT device reaches a opera=
tor<br>
&nbsp;&nbsp; configured threshold when allocating resources.&nbsp; The thre=
shold<br>
&nbsp;&nbsp; reached events are described in the section above.&nbsp; The f=
ollowing is<br>
&nbsp;&nbsp; a template of the individual events.<br>
<br>
5.6.8.1.&nbsp; Address pool high or low threshold reached<br>
<br>
&nbsp;&nbsp; This event is generated when the high or low threshold is reac=
hed for<br>
&nbsp;&nbsp; the address pool.&nbsp; The template is the same for both high=
 and low<br>
&nbsp;&nbsp; threshold events<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp; | Size (bits) | =
Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbs=
p;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp; natInstanceID&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbs=
p; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; | natThresholdEvent |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp; natPoolID&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbs=
p;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp; configuredLimit&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp; Table 16: Address pool high/low threshold reached =
event template<br>
<br>
5.6.8.2.&nbsp; Address and port high threshold reached<br>
<br>
&nbsp;&nbsp; This event is generated when the high threshold is reached for=
 the<br>
&nbsp;&nbsp; address pool and ports.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp; | Size (bits) | =
Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Yes&nbs=
p;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp; natInstanceID&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; =
|<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbs=
p; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; | natThresholdEvent |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; |&nbsp; configuredLimit&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &#43;-------------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 17: Address port high threshold =
reached event template<br>
<br>
5.6.8.3.&nbsp; Per-user Address and port high threshold reached<br>
<br>
&nbsp;&nbsp; This event is generated when the high threshold is reached for=
 the<br>
&nbsp;&nbsp; per-user address pool and ports.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp; | Size (bits) |&nbsp;&=
nbsp; Mandatory&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp; natInstanceID&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; natThr=
esholdEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3=
2 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp; =
configuredLimit&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | vlanID/ingre=
ssVRFID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; source=
IPv4 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 | Y=
es for NAT44 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp; source=
IPv6 address |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 128 | Yes fo=
r NAT64 |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;---------=
------------&#43;-------------&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp; Table 18: Per-user Address port high threshold reached event t=
emplate<br>
<br>
5.6.8.4.&nbsp; Global Address mapping high threshold reached<br>
<br>
&nbsp;&nbsp; This event is generated when the high is reached for the per-u=
ser<br>
&nbsp;&nbsp; address pool and ports.&nbsp; This is generated only by NAT de=
vices that<br>
&nbsp;&nbsp; use a address pooling behavior of paired.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#=
43;---------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp; | Size (bi=
ts) | Mandatory |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#=
43;---------------------&#43;-------------&#43;-----------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp; natInstanceID&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&=
nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
|&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 8 |&nbsp;&nbs=
p;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp; natThresholdEvent&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp; configuredLimit&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | =
vlanID/ingressVRFID |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
 32 |&nbsp;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#=
43;---------------------&#43;-------------&#43;-----------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 19: Global Address mapping high =
threshold reached event<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; template<br>
<br>
5.6.9.&nbsp; Address binding create and delete events<br>
<br>
&nbsp;&nbsp; These events will be generated when a NAT device binds a local=
<br>
&nbsp;&nbsp; address with a global address and when the global address is f=
reed.<br>
&nbsp;&nbsp; This binding event happens when the first packet of the first =
flow<br>
&nbsp;&nbsp; from a host in the private realm.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp; | Size (bits) |&nbsp;&nbsp; Mandatory&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<=
br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv4 a=
ddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; 32 | Yes for NAT44 |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv6 a=
ddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; 128 | Yes for NAT64 |<br>
&nbsp;&nbsp;&nbsp;&nbsp; | Translated Source IPv4 Address |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp; Table 20: NAT Address Binding template<br>
<br>
5.6.10.&nbsp; Port block allocation and de-allocation<br>
<br>
&nbsp;&nbsp; This event will be generated when a NAT device allocates/de-al=
locates<br>
&nbsp;&nbsp; ports in a bulk fashion, as opposed to allocating a port on a =
per<br>
&nbsp;&nbsp; flow basis.<br>
<br>
&nbsp;&nbsp; portRangeStart represents the starting value of the range.<br>
<br>
&nbsp;&nbsp; portRangeEnd represents the ending value of the range.<br>
<br>
&nbsp;&nbsp; NAT devices would do this in order to reduce logs and potentia=
lly to<br>
&nbsp;&nbsp; limit the number of connections a subscriber is allowed to use=
.&nbsp; In<br>
&nbsp;&nbsp; the following Port Block allocation template, the portRangeSta=
rt and<br>
&nbsp;&nbsp; portRangeEnd must be specified.<br>
<br>
<br>
Sivakumar &amp; Penno&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Expires Aug=
ust 15, 2014&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; [Page 17]<br>
<br>
Internet-Draft&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IPFIX =
IEs for NAT logging&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; F=
ebruary 2014<br>
<br>
&nbsp;&nbsp; It is up to the implementation to choose to consolidate log re=
cords<br>
&nbsp;&nbsp; in case two consecutive port ranges for the same user are allo=
cated<br>
&nbsp;&nbsp; or freed.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; Field Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp; | Size (bits) |&nbsp;&nbsp; Mandatory&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp; timeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 64 |&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
natInstanceID&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; natEvent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp; 8 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<=
br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv4 a=
ddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; 32 | Yes for NAT44 |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; sourceIPv6 a=
ddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; 128 | Yes for NAT64 |<br>
&nbsp;&nbsp;&nbsp;&nbsp; | Translated Source IPv4 Address |&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 32 |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Y=
es&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
portRangeStart&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp; portRangeEnd&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 16 |&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp; No&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br>
&nbsp;&nbsp;&nbsp;&nbsp; &#43;--------------------------------&#43;--------=
-----&#43;---------------&#43;<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Table 21=
: NAT Port Block Allocation event template<br>
<br>
6.&nbsp; Encoding<br>
<br>
6.1.&nbsp; IPFIX<br>
<br>
&nbsp;&nbsp; This document uses IPFIX as the encoding mechanism to describe=
 the<br>
&nbsp;&nbsp; logging of NAT events.&nbsp; However, the information that sho=
uld be<br>
&nbsp;&nbsp; logged SHOULD be the same irrespective of what kind of encodin=
g<br>
&nbsp;&nbsp; scheme is used.&nbsp; IPFIX is chosen because is it an IETF st=
andard that<br>
&nbsp;&nbsp; meets all the needs for a reliable logging mechanism.&nbsp; IP=
FIX provides<br>
&nbsp;&nbsp; the flexibility to the logging device to define the data sets =
that it<br>
&nbsp;&nbsp; is logging.&nbsp; The IEs specified for logging MUST be the sa=
me<br>
&nbsp;&nbsp; irrespective of the encoding mechanism used.<br>
<br>
7.&nbsp; Acknowledgements<br>
<br>
&nbsp;&nbsp; Thanks to Dan Wing, Selvi Shanmugam, Mohamed Boucadir, Jacni Q=
in<br>
&nbsp;&nbsp; Ramji Vaithianathan, Simon Perreault, Jean-Francois Tremblay, =
Paul<br>
&nbsp;&nbsp; Aitken and Julia Renouard for their review and comments.<br>
<br>
8.&nbsp; IANA Considerations<br>
<br>
&nbsp;&nbsp; The following information elements are requested from IANA IPF=
IX<br>
&nbsp;&nbsp; registry.<br>
<br>
&nbsp;&nbsp; natInstanceId<br>
<br>
&nbsp;&nbsp; externalAddressRealm<br>
<br>
&nbsp;&nbsp; natLimitEvent<br>
<br>
9.&nbsp; Management Considerations<br>
<br>
&nbsp;&nbsp; This section considers requirements for management of the log =
system<br>
&nbsp;&nbsp; to support logging of the events described above.&nbsp; It fir=
st covers<br>
&nbsp;&nbsp; requirements applicable to log management in general.&nbsp; An=
y additional<br>
&nbsp;&nbsp; standardization required to fullfil these requirements is out =
of<br>
&nbsp;&nbsp; scope of the present document.&nbsp; Some management considera=
tions is<br>
&nbsp;&nbsp; covered in [I-D.behave-syslog-nat-logging].&nbsp; This documen=
t covers the<br>
&nbsp;&nbsp; additional considerations.<br>
<br>
9.1.&nbsp; Ability to collect events from multiple NAT devices<br>
<br>
&nbsp;&nbsp; An IPFIX collector should be able to collect events from multi=
ple NAT<br>
&nbsp;&nbsp; devices and be able to decipher events based on the sourceID i=
n the<br>
&nbsp;&nbsp; IPFIX header.<br>
<br>
9.2.&nbsp; Ability to suppress events<br>
<br>
&nbsp;&nbsp; The exhaustion events can be overwhelming during traffic burst=
s and<br>
&nbsp;&nbsp; hence should be handled by the NAT devices to rate limit them =
before<br>
&nbsp;&nbsp; sending them to the collectors.&nbsp; For eg. when the port ex=
haustion<br>
&nbsp;&nbsp; happens during bursty conditions, instead of sending a port<br=
>
&nbsp;&nbsp; exhaustion event for every packet, the exhaustion events shoul=
d be<br>
&nbsp;&nbsp; rate limited by the NAT device.<br>
<br>
10.&nbsp; Security Considerations<br>
<br>
&nbsp;&nbsp; None.<br>
<br>
11.&nbsp; References<br>
<br>
11.1.&nbsp; Normative References<br>
<br>
&nbsp;&nbsp; [RFC2119]&nbsp; Bradner, S., &quot;Key words for use in RFCs t=
o Indicate<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Requirement Levels&quot;, BCP 14, RFC 2119, March 1997.<br>
<br>
&nbsp;&nbsp; [RFC2663]&nbsp; Srisuresh, P. and M. Holdrege, &quot;IP Networ=
k Address<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Translator (NAT) Terminology and Considerations&quot;, RFC<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; 2663, August 1999.<br>
<br>
&nbsp;&nbsp; [RFC4787]&nbsp; Audet, F. and C. Jennings, &quot;Network Addre=
ss Translation<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; (NAT) Behavioral Requirements for Unicast UDP&quot;, BCP 127,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; RFC 4787, January 2007.<br>
<br>
&nbsp;&nbsp; [RFC5382]&nbsp; Guha, S., Biswas, K., Ford, B., Sivakumar, S.,=
 and P.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Srisuresh, &quot;NAT Behavioral Requirements for TCP&quot;, BCP 142,<br=
>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; RFC 5382, October 2008.<br>
<br>
&nbsp;&nbsp; [RFC6146]&nbsp; Bagnulo, M., Matthews, P., and I. van Beijnum,=
 &quot;Stateful<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; NAT64: Network Address and Protocol Translation from IPv6<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Clients to IPv4 Servers&quot;, RFC 6146, April 2011.<br>
<br>
&nbsp;&nbsp; [RFC6302]&nbsp; Durand, A., Gashinsky, I., Lee, D., and S. She=
ppard,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &quot;Logging Recommendations for Internet-Facing Servers&quot;, BCP<br=
>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; 162, RFC 6302, June 2011.<br>
<br>
&nbsp;&nbsp; [RFC6888]&nbsp; Perreault, S., Yamagata, I., Miyakawa, S., Nak=
agawa, A.,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; and H. Ashida, &quot;Common Requirements for Carrier-Grade NATs<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; (CGNs)&quot;, BCP 127, RFC 6888, April 2013.<br>
<br>
11.2.&nbsp; Informative References<br>
<br>
&nbsp;&nbsp; [I-D.ietf-behave-syslog-nat-logging]<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Chen, Z., Zhou, C., Tsou, T., and T. Taylor, &quot;Syslog<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Format for NAT Logging&quot;, draft-ietf-behave-syslog-nat-<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; logging-06 (work in progress), January 2014.<br>
<br>
&nbsp;&nbsp; [IPFIX-IANA]<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; IANA, &quot;IPFIX Information Elements registry&quot;,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; <a moz-do-not-send=3D"true" class=3D"moz-txt-link-rfc2396E" href=3D"htt=
p://www.iana.org/assignments/ipfix">
&lt;http://www.iana.org/assignments/ipfix&gt;</a>.<br>
<br>
&nbsp;&nbsp; [RFC5101bis]<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Claise, B. and B. Trammel, &quot;Specification of the IP Flow<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Information eXport (IPFIX) Protocol for the Exchange of<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Flow Information&quot;, July 2013.<br>
<br>
&nbsp;&nbsp; [RFC5102bis]<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Claise, B. and B. Trammel, &quot;Information Model for IP Flow<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; Information eXport (IPFIX)&quot;, February 2013.<br>
<br>
&nbsp;&nbsp; [RFC5470]&nbsp; Sadasivan, G., Brownlee, N., Claise, B., and J=
. Quittek,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; &quot;Architecture for IP Flow Information Export&quot;, RFC 5470,<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; March 2009.<br>
<br>
Authors' Addresses<br>
<br>
&nbsp;&nbsp; Senthil Sivakumar<br>
&nbsp;&nbsp; Cisco Systems<br>
&nbsp;&nbsp; 7100-8 Kit Creek Road<br>
&nbsp;&nbsp; Research Triangle Park, North Carolina&nbsp; 27709<br>
&nbsp;&nbsp; USA<br>
<br>
&nbsp;&nbsp; Phone: &#43;1 919 392 5158<br>
<br>
&nbsp;&nbsp; Renaldo Penno<br>
&nbsp;&nbsp; Cisco Systems<br>
&nbsp;&nbsp; 170 W Tasman Drive<br>
&nbsp;&nbsp; San Jose, California&nbsp; 95035<br>
&nbsp;&nbsp; USA<br>
<br>
&nbsp;&nbsp; Email: <a moz-do-not-send=3D"true" class=3D"moz-txt-link-abbre=
viated" href=3D"mailto:repenno@cisco.com">
repenno@cisco.com</a><br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
Sivakumar &amp; Penno&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Expires Aug=
ust 15, 2014&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; [Page 21]</font></div>
</div>
</span></blockquote>
<br>
</div>
</div>
</span>
</body>
</html>

--_000_CFAA34BB106C60ssenthilciscocom_--

