From owner-nat@livingston.com  Mon Sep 11 11:45:33 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id LAA05250
	for <nat-archive@odin.ietf.org>; Mon, 11 Sep 2000 11:45:33 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id IAA10702;
	Mon, 11 Sep 2000 08:35:20 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id IAA04638
	for nat-outgoing; Mon, 11 Sep 2000 08:30:08 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
From: "Joris Dobbelsteen" <joris.dobbelsteen@mail.com>
To: "IPng WG (E-mail)" <ipng@sunroof.eng.sun.com>,
        "NAT WG (E-mail)" <nat@livingston.com>
Subject: (NAT) IPv6 and NAT
Date: Mon, 11 Sep 2000 17:27:21 +0200
Message-ID: <000501c01c04$c94875f0$0d0aa8c0@THUIS.LOCAL>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook CWS, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.3018.1300
Importance: Normal
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: "Joris Dobbelsteen" <joris.dobbelsteen@mail.com>
Content-Transfer-Encoding: 7bit

Maybe an issue for the IPv6 and NAT Workgroups.

NAT was proposed as a temporary solution for the shortage of IP address,
which is solved with the IPv6 protocol. Currently I don't expect IPv6 to be
deployed soon (within 1 or 2 years). My ISP, nor many ISPs, aren't promoting
IPv6 yet, nor Microsoft provides IPv6 support for it's OSes.
But as finally IPv6 has been deployed world-wide, what will we do with NAT?

A disadvantage of NAT is that some protocols don't work good/correctly
through NAT. Here NAT broke the principle of the Internet, where every node
should be able to have bidirectional and end-to-end communication. FTP and
many games require this to operate correctly.

However, some scenarios where NAT provides THE solution, are for
* private networks that may not be exposed to the Internet   and
* for networks that have only one IP address available to use on the
Internet,
while host on the private network are required to make 'direct' connections
to the Internet.

I don't think NAT should be made obsolete or unneeded after IPv6 has been
deployed, but rather to be offered for some purposes on small and home
networks. Most companies and bussinesses (even small ones) will be able to
afford a dedicated Internet Connection with a couple IP addresses,
esspecially after IPv6 has been deployed.
However I don't expect my ISP to provide me more than one IP address,
because I don't have a dedicated connection (yet) and I even haven't got one
static IP address (just DHCP). Also I want to separate 'MY' network from the
Internet, and don't install more network adapters into computers and lay
networking cable than needed. This requirement without having to make
strange configurations to any other computers on the network.


That's what's so good about NAT, from my point of view....



- Joris

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@livingston.com  Mon Sep 11 12:10:09 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id MAA05788
	for <nat-archive@odin.ietf.org>; Mon, 11 Sep 2000 12:10:08 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id IAA11398;
	Mon, 11 Sep 2000 08:59:38 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id JAA09913
	for nat-outgoing; Mon, 11 Sep 2000 09:01:40 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
Message-Id: <4.3.1.2.20000911085544.00bfacf0@pop3.ipverse.com>
X-Sender: matt@ipverse.com@pop3.ipverse.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.1
Date: Mon, 11 Sep 2000 09:00:58 -0700
To: "Joris Dobbelsteen" <joris.dobbelsteen@mail.com>
From: Matt Holdrege <matt@ipverse.com>
Subject: Re: (NAT) IPv6 and NAT
Cc: "IPng WG (E-mail)" <ipng@sunroof.eng.sun.com>,
        "NAT WG (E-mail)" <nat@livingston.com>
In-Reply-To: <000501c01c04$c94875f0$0d0aa8c0@THUIS.LOCAL>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: Matt Holdrege <matt@ipverse.com>

Joris,

Before you post to these groups, it would be a real good idea to read some 
of the RFC's and Drafts that have been produced on this topic. 
Specifically, you should read 
http://www.ietf.org/internet-drafts/draft-iab-nat-implications-09.txt and 
http://www.ietf.org/internet-drafts/draft-ietf-nat-protocol-complications-04.txt



At 05:27 PM 9/11/00 +0200, Joris Dobbelsteen wrote:
>Maybe an issue for the IPv6 and NAT Workgroups.
>
>NAT was proposed as a temporary solution for the shortage of IP address,
>which is solved with the IPv6 protocol. Currently I don't expect IPv6 to be
>deployed soon (within 1 or 2 years). My ISP, nor many ISPs, aren't promoting
>IPv6 yet, nor Microsoft provides IPv6 support for it's OSes.
>But as finally IPv6 has been deployed world-wide, what will we do with NAT?
>
>A disadvantage of NAT is that some protocols don't work good/correctly
>through NAT. Here NAT broke the principle of the Internet, where every node
>should be able to have bidirectional and end-to-end communication. FTP and
>many games require this to operate correctly.
>
>However, some scenarios where NAT provides THE solution, are for
>* private networks that may not be exposed to the Internet   and
>* for networks that have only one IP address available to use on the
>Internet,
>while host on the private network are required to make 'direct' connections
>to the Internet.
>
>I don't think NAT should be made obsolete or unneeded after IPv6 has been
>deployed, but rather to be offered for some purposes on small and home
>networks. Most companies and bussinesses (even small ones) will be able to
>afford a dedicated Internet Connection with a couple IP addresses,
>esspecially after IPv6 has been deployed.
>However I don't expect my ISP to provide me more than one IP address,
>because I don't have a dedicated connection (yet) and I even haven't got one
>static IP address (just DHCP). Also I want to separate 'MY' network from the
>Internet, and don't install more network adapters into computers and lay
>networking cable than needed. This requirement without having to make
>strange configurations to any other computers on the network.
>
>
>That's what's so good about NAT, from my point of view....
>
>
>
>- Joris
>
>-
>To unsubscribe, email 'majordomo@livingston.com' with
>'unsubscribe nat' in the body of the message.

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@livingston.com  Mon Sep 11 12:17:29 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id MAA05870
	for <nat-archive@odin.ietf.org>; Mon, 11 Sep 2000 12:17:29 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id JAA11552;
	Mon, 11 Sep 2000 09:03:03 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id JAA10787
	for nat-outgoing; Mon, 11 Sep 2000 09:06:32 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
Message-ID: <00ce01c01c22$d5a80cc0$11e2130a@spandex>
From: "Melinda Shore" <mshore@cisco.com>
To: "Joris Dobbelsteen" <joris.dobbelsteen@mail.com>,
        "IPng WG (E-mail)" <ipng@sunroof.eng.sun.com>,
        "NAT WG (E-mail)" <nat@livingston.com>
References: <000501c01c04$c94875f0$0d0aa8c0@THUIS.LOCAL>
Subject: Re: (NAT) IPv6 and NAT
Date: Mon, 11 Sep 2000 12:02:27 -0700
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2615.200
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2615.200
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: "Melinda Shore" <mshore@cisco.com>
Content-Transfer-Encoding: 7bit

>From: Joris Dobbelsteen <joris.dobbelsteen@mail.com>
>To: IPng WG (E-mail) <ipng@sunroof.eng.sun.com>; NAT WG (E-mail)
><nat@livingston.com>
>Sent: Monday, September 11, 2000 8:27 AM
>Subject: (NAT) IPv6 and NAT


> I don't think NAT should be made obsolete or unneeded after
IPv6 has been
> deployed, but rather to be offered for some purposes on small
and home
> networks.

A couple of things:

1) I don't think that anybody is in the position
of being able to mandate NAT out of existence -
if service providers/network operators feel that
there's justification for continuing to translate
addresses, they will do just that

2) In voice services there's a requirement to be
able to hide calling party addresses on a policy
basis.  NAT is one way to effect this (although
arguably not the best, given the numerous problems
it causes).  A few people in the voice community
are claiming, however, that no terminal should
have a public IP address and that there should
be "address policy domains."  I don't find their
arguments for it particularly compelling and I'm
not even going to try to represent them, but my
guess is that this is going to be an argument
we'll be having in a year or so.

At any rate, I think that point 1 above is the
salient one.

Melinda


-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@livingston.com  Mon Sep 11 12:40:15 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id MAA06178
	for <nat-archive@odin.ietf.org>; Mon, 11 Sep 2000 12:40:15 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id JAA12402;
	Mon, 11 Sep 2000 09:29:42 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id JAA15825
	for nat-outgoing; Mon, 11 Sep 2000 09:31:52 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
X-MimeOLE: Produced By Microsoft Exchange V6.0.4417.0
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Subject: RE: (NAT) IPv6 and NAT
Date: Mon, 11 Sep 2000 09:27:50 -0700
Message-ID: <CC2E64D4B3BAB646A87B5A3AE97090420D5F0237@speak.platinum.corp.microsoft.com>
Thread-Topic: (NAT) IPv6 and NAT
Thread-Index: AcAcBw/npJ3Y0GmVRj6YQLXC7qN+QwAA79sQ
From: "Tony Hain" <tonyhain@exchange.microsoft.com>
To: "Joris Dobbelsteen" <joris.dobbelsteen@mail.com>,
        "IPng WG (E-mail)" <ipng@sunroof.eng.sun.com>,
        "NAT WG (E-mail)" <nat@livingston.com>
X-OriginalArrivalTime: 11 Sep 2000 16:30:40.0543 (UTC) FILETIME=[9FACD2F0:01C01C0D]
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by server.livingston.com id JAA15820
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: "Tony Hain" <tonyhain@exchange.microsoft.com>
Content-Transfer-Encoding: 8bit

Just to clarify, NAT does not provide isolation from the Internet, route
filtering does that. The inbound filtering that happens is a function of
lack of a route in the NAT, not the fact it is translating addresses.
IPv6 has a defined function for this, called Site Local. These addresses
are filtered at the site boundary router, providing more security than
'where is this port mapped to now?' functions.

It is expected that ISPs will be allocating /48 to customers, and for
those that don't support IPv6 the IPv4 address provides a /48 using
6to4. With 64k subnets available there should be no reason to build
perverse configurations, and no need for translating the addresses. As
you note many things do not work correctly without end-to-end address
integrity, so why preclude them by continuing down the NAT path? Each of
the items you list as values are solved in a cleaner way by IPv6 so just
move to it.

Tony

While I am the Program Manager for IPv6 at Microsoft, the above comments
are mine and should not be construed as related to my employer.



-----Original Message-----
From: Joris Dobbelsteen [mailto:joris.dobbelsteen@mail.com]
Sent: Monday, September 11, 2000 8:27 AM
To: IPng WG (E-mail); NAT WG (E-mail)
Subject: (NAT) IPv6 and NAT


Maybe an issue for the IPv6 and NAT Workgroups.

NAT was proposed as a temporary solution for the shortage of IP address,
which is solved with the IPv6 protocol. Currently I don't expect IPv6 to
be
deployed soon (within 1 or 2 years). My ISP, nor many ISPs, aren't
promoting
IPv6 yet, nor Microsoft provides IPv6 support for it's OSes.
But as finally IPv6 has been deployed world-wide, what will we do with
NAT?

A disadvantage of NAT is that some protocols don't work good/correctly
through NAT. Here NAT broke the principle of the Internet, where every
node
should be able to have bidirectional and end-to-end communication. FTP
and
many games require this to operate correctly.

However, some scenarios where NAT provides THE solution, are for
* private networks that may not be exposed to the Internet   and
* for networks that have only one IP address available to use on the
Internet,
while host on the private network are required to make 'direct'
connections
to the Internet.

I don't think NAT should be made obsolete or unneeded after IPv6 has
been
deployed, but rather to be offered for some purposes on small and home
networks. Most companies and bussinesses (even small ones) will be able
to
afford a dedicated Internet Connection with a couple IP addresses,
esspecially after IPv6 has been deployed.
However I don't expect my ISP to provide me more than one IP address,
because I don't have a dedicated connection (yet) and I even haven't got
one
static IP address (just DHCP). Also I want to separate 'MY' network from
the
Internet, and don't install more network adapters into computers and lay
networking cable than needed. This requirement without having to make
strange configurations to any other computers on the network.


That's what's so good about NAT, from my point of view....



- Joris

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.
-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@livingston.com  Mon Sep 11 13:58:51 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id NAA07198
	for <nat-archive@odin.ietf.org>; Mon, 11 Sep 2000 13:58:50 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id KAA14037;
	Mon, 11 Sep 2000 10:49:27 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id KAA00961
	for nat-outgoing; Mon, 11 Sep 2000 10:52:37 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
From: "Joris Dobbelsteen" <joris.dobbelsteen@mail.com>
To: "IPng WG (E-mail)" <ipng@sunroof.eng.sun.com>,
        "NAT WG (E-mail)" <nat@livingston.com>
Subject: RE: (NAT) IPv6 and NAT
Date: Mon, 11 Sep 2000 19:49:19 +0200
Message-ID: <000801c01c18$9e67ced0$0d0aa8c0@THUIS.LOCAL>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook CWS, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.3018.1300
Importance: Normal
In-Reply-To: <006a01c01c10$161715c0$adfb10ac@francislaptop>
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: "Joris Dobbelsteen" <joris.dobbelsteen@mail.com>
Content-Transfer-Encoding: 7bit

Looks like a *dame* stupid question, so I suppose it is....

However I will explain why I actually did ask this:
Maybe I don't explain things to good (my english sucks at this point)....

Assume i'm just an ordinary home(!) user that dials (with a 50Kbps modem) to
an (free) ISP and requests IP addresses using DHCP, you get only ONE, not a
subnet (such account I don't have and can't afford: it ain't free, so far I
know). So I don't benefit from the 64K (or at least 4 Internet IP
addresses)....

Now I do have a (little) computer network, that must be connected to the
Internet.
Installing a HTTP proxy works fine for HTTP, FTP and Gopher. SMTP and POP3
can also be solved (with some more clever software). SOCKS can handle
clients that support that (like ICQ, etc).
BUT what about my software that does not support this, such as SOCKS???
Things like this are the problem, the - lets call it - 'bad' software...

On my current network NAT would solve this problem, what should I do when I
have IPv6 deployed?







Matt,

I will read the docs you given (today, 11th, I'm to busy)




Christian,

I will look at MS its docs (and downloads)...





-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@livingston.com  Mon Sep 11 14:04:18 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id OAA07279
	for <nat-archive@odin.ietf.org>; Mon, 11 Sep 2000 14:04:17 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id KAA14159;
	Mon, 11 Sep 2000 10:51:17 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id KAA01440
	for nat-outgoing; Mon, 11 Sep 2000 10:55:15 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
Message-Id: <4.3.1.2.20000911090719.00c2f180@pop3.ipverse.com>
X-Sender: matt@ipverse.com@pop3.ipverse.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.1
Date: Mon, 11 Sep 2000 09:09:40 -0700
To: nat@livingston.com, sob@harvard.edu, mankin@east.isi.edu
From: Matt Holdrege <matt@ipverse.com>
Subject: (NAT) draft-ietf-nat-protocol-complications-04.txt completes last
  call
Cc: srisuresh@yahoo.com
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: Matt Holdrege <matt@ipverse.com>

Today completes the WG last call for the protocol complications draft. The 
NAT WG recommends it to the IESG for publishing as an Informational RFC.

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@livingston.com  Mon Sep 11 14:05:54 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id OAA07299
	for <nat-archive@odin.ietf.org>; Mon, 11 Sep 2000 14:05:53 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id KAA14509;
	Mon, 11 Sep 2000 10:56:07 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id LAA02452
	for nat-outgoing; Mon, 11 Sep 2000 11:00:06 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
Message-ID: <39BD1D8F.18BE3BA8@cisco.com>
Date: Mon, 11 Sep 2000 10:59:43 -0700
From: Eliot Lear <lear@cisco.com>
Organization: Cisco Systems
X-Mailer: Mozilla 4.5 [en] (Win95; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Joris Dobbelsteen <joris.dobbelsteen@mail.com>
CC: "IPng WG (E-mail)" <ipng@sunroof.eng.sun.com>,
        "NAT WG (E-mail)" <nat@livingston.com>
Subject: Re: (NAT) IPv6 and NAT
References: <000801c01c18$9e67ced0$0d0aa8c0@THUIS.LOCAL>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: Eliot Lear <lear@cisco.com>
Content-Transfer-Encoding: 7bit

First, you probably don't realize what a storm you are treading into,
and so let me suggest that this NOT become a flame fest.

Technically speaking there is nothing that stops you from using NAT with
IPv6.  The issue remains the limitations it could cause you, should you
choose to offer services from one of your workstations.  Please read
Tony Hain's document carefully.
--
Eliot Lear
lear@cisco.com
-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@livingston.com  Tue Sep 12 00:56:25 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id AAA14276
	for <nat-archive@odin.ietf.org>; Tue, 12 Sep 2000 00:56:24 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id VAA22546;
	Mon, 11 Sep 2000 21:47:06 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id VAA10532
	for nat-outgoing; Mon, 11 Sep 2000 21:48:20 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
Message-ID: <20000912044732.13095.qmail@web1403.mail.yahoo.com>
Date: Mon, 11 Sep 2000 21:47:32 -0700 (PDT)
From: Pyda Srisuresh <srisuresh@yahoo.com>
Subject: Fwd: (NAT) draft-ietf-nat-protocol-complications-04.txt completes last  call
To: sob@harvard.edu, mankin@east.isi.edu
Cc: nat@livingston.com
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: Pyda Srisuresh <srisuresh@yahoo.com>

The NAT WG chairs also recommend <draft-ietf-nat-traditional-04.txt> 
to the IESG for publication as informational RFC. The above draft 
cleared NAT WG last call a while back. Thanks.

regards,
suresh & Matt
 

--- Matt Holdrege <matt@ipverse.com> wrote:
> Date: Mon, 11 Sep 2000 09:09:40 -0700
> To: nat@livingston.com, sob@harvard.edu, mankin@east.isi.edu
> From: Matt Holdrege <matt@ipverse.com>
> Subject: (NAT) draft-ietf-nat-protocol-complications-04.txt completes last
>   call
> CC: srisuresh@YAHOO.COM
> Reply-to: Matt Holdrege <matt@ipverse.com>
> 
> Today completes the WG last call for the protocol complications draft. The 
> NAT WG recommends it to the IESG for publishing as an Informational RFC.
> 
> -
> To unsubscribe, email 'majordomo@livingston.com' with
> 'unsubscribe nat' in the body of the message.


=====


__________________________________________________
Do You Yahoo!?
Yahoo! Mail - Free email you can access from anywhere!
http://mail.yahoo.com/
-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@livingston.com  Thu Sep 14 15:22:20 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id PAA22860
	for <nat-archive@odin.ietf.org>; Thu, 14 Sep 2000 15:22:19 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id MAA03082;
	Thu, 14 Sep 2000 12:08:24 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id MAA01452
	for nat-outgoing; Thu, 14 Sep 2000 12:09:05 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
From: "Joris Dobbelsteen" <joris.dobbelsteen@mail.com>
To: "IPng WG (E-mail)" <ipng@sunroof.eng.sun.com>,
        "NAT WG (E-mail)" <nat@livingston.com>
Subject: RE: (NAT) IPv6 and NAT
Date: Thu, 14 Sep 2000 20:56:19 +0200
Message-ID: <001101c01e7e$f23a6640$0d0aa8c0@THUIS.LOCAL>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="US-ASCII"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook CWS, Build 9.0.2416 (9.0.2910.0)
In-Reply-To: <Pine.GSO.3.96.1000913180234.11779D-100000@da1server>
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
Importance: Normal
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: "Joris Dobbelsteen" <joris.dobbelsteen@mail.com>
Content-Transfer-Encoding: 7bit

I've read the drafts about NAT (finally),

As Dan said, NAT will be used, what is not a problem if it's only - AND
ONLY - used by home users that want to route there network to the Internet
and have a simple (free) Internet account, that only provides one
public/Internet IP address to them.

Let's assume MOST (not all) home users won't make much use from all the
security services that are provides, like IPSec (SSL, etc. with e.g. HTTPS
is not a problem). They also don't have complex networks and only want to be
able to use a web browser, send/receive e-mail and play a game on the
Internet. Most of these services can be done over NAT, usually home users
have only one network link, and a quite simple network.
Actually, I like it on a home LAN, even with it's limitations....

For better explanation, I mean with a Home LAN a network consisting of a
single link with no routers, and (maybe) only one NAT router to the
Internet.

Businesses usually have more complex networks, require security services and
things that don't work with NAT. For them NAT should be highly discouraged.

However now the problem that arises, most computers will not be equipped
with two network cards, where one is for the private network, and the other
one for the Internet.
Hope you understand what I mean???? Let me explain a bit better before you
give comment (most likely needed)...


Let's take the Microsoft Windows platform for example (e.g. Windows 98).
This is the only platform where I have experience with IPv4 transports.

Your computer is connected to a private network and has a private IP
address. So why not add the public IP address to the same adapter to be used
for the Internet connection?
Well, Windows doesn't assign services (like file and printer sharing) to IP
address, but to the Network adapter itself, regardless of any network
protocol and it's configuration. This will mean everybody on the private
network AND the Internet will access your computer using the MS File and
Printer Sharing! This is only one service where the problem arises...

And why can't we install an additional Network Adapter?
This solution is not cost-efficient: It will require around $100 for every
computer that needs a connection to the Internet, and not counting the cost
for the UTP hubs needed.


The solution to this problem is probably VPN, (IP-over-IP) tunneling or
something similar. Maybe there are other solutions, but I'm not familiar
with them or don't know of there existence.
Maybe that software implementers can provide a virtual device driver that
simulates a network adapter connected to the Internet and has IP tunneling.
But I leave this discussion to the software implementers.


Before I forget, some of you talked about Interface-local, link-local and
site-local IPv6 address, but these cannot be used on the Internet, nor
routed to the Internet without the translation that is subjected to retire
after IPv6 (just like the private IPv4 addresses).




- Joris



> -----Original Message-----
> From: owner-ipng@sunroof.eng.sun.com
> [mailto:owner-ipng@sunroof.eng.sun.com]On Behalf Of Greg Maxwell
> Sent: donderdag 14 september 2000 0:32
> To: Dan Lanciani
> Cc: ipng@sunroof.eng.sun.com
> Subject: Re: (NAT) IPv6 and NAT
>
>
> On Wed, 13 Sep 2000, Dan Lanciani wrote:
>
> [snip]
> > discourage them from consuming it all.  Offer the v6 space
> on the terms that v4
> > space was once available (i.e., free with nominal
> justification documentation)
> > and I'm sure people will use it.
> [snip]
> > The same argument applies to NAT.  If ISPs make it
> expensive to get extra v6
> > addresses (based on the justification that addresses used
> to be scarce?) then
> > people will use NAT with IPv6.  If ISPs make "stable" v6
> addresses (i.e., ones
> > that they do not deliberately renumber frequently) a
> premium service then
> > people will use NAT.
>
> Simple. Require that any group providing packet transport services (an
> ISP) to provide address space to their users under the same set of
> qualifications required for the provider to obtain address space at a
> maximum.
>
> This would be enforced by making compliance mandatory for
> address space
> allocations (thus making the requirement recursive (i.e users
> of user of
> users).
>
> This would not effect a providers ability to otherwise sell transport
> services under whatever contract their customers and they agree opon.
>
> It would also simplify justification documentation for providers, just
> concatenate their user's justification documents with their
> own to form
> their application.
>
> I believe this is the only way to break the idea that network
> addresses
> are a valuable commodity and to prevent NAT.
>
> > Although the standard claim is that NAT breaks the end-
> > to-end model we all like (and note that I have personally
> never liked NAT),
> > NAT shines at preserving the stable-address model that is
> deeply embedded in
> > many protocols and applications.  NAT has already proved
> itself:  many useful
> > applications work just fine in spite of the loss of the
> end-to-end model.
>
> NAT is abominable. It subtlety breaks things and hides the
> cause. It is
> full of exceptions and gotchas.
>
> One layer of NAT can be manageable when the network is small
> and has only
> a single outside path.
>
> However, as networks become large and better innerconnected, peering
> address conflicts on NATed networks necessitate multiple layers of NAT
> causing a complicated 'WHO's on first?' situation. Furthermore, the
> statefulness required by many->one NAT (and one-one for some
> protocols)
> makes many types of highly-available configuration virtually
> impossible to
> achieve. Indeed, virtually all NAT solutions force there to
> be a single
> point of failure or a single site of failure.
>
> NAT is a descent into madness.
>
> > I happen to think that ISPs will charge a premium for
> multiple and/or stable
> > v6 addresses because that is the status quo and because the
> market will bear
> > it.
>
> I agree unless they are required not to practice this harmful
> activity.
>
> The legally required goal of a corporation is to maxmize shareholder
> profits. This goal may at times conflict with the goal of providing a
> global, scalable, available, and optimally useful network
> infrastructure.
>
> Indeed, a heavily NATed internet enviroment would create many
> additional
> network contracting and consulting jobs.
>
> > Thus, I suspect that NAT will remain quite active if/when
> IPv6 is deployed.
>
> If it does IPv6 will fail.
> An IPv6 NATatopia would offer no benifit to consumers or
> providers over an
> IPv4 NATatopia.
>
> > I think this is unfortunate--again, I'm no fan of NAT--but
> it's probably too
> > late to do anything.  While it certainly would have been
> possible to structure
> > IPv6 in such a way that end users could allocate identity
> addresses independent
> [snip]
>
> > So the market pressures will continue to operate in an IPv6
> environment just as
> > they have in the IPv4 one.  All IMHO, of course...
>
> I think the solution is obvious: If a detrimental behavior is expected
> then simply forbid it.
>
> There is no point to being wishey-washey. Progress is not made by
> the mediocre.
>
> Gregory Maxwell
>
> --
> The comments and opinions expressed herein are those of the
> author of this
> message and may not reflect the policies of the Martin County Board of
> County Commissioners.
>
>
> --------------------------------------------------------------------
> IETF IPng Working Group Mailing List
> IPng Home Page:                      http://playground.sun.com/ipng
> FTP archive:                      ftp://playground.sun.com/pub/ipng
> Direct all administrative requests to majordomo@sunroof.eng.sun.com
> --------------------------------------------------------------------
>

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@livingston.com  Fri Sep 15 00:58:48 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id AAA02283
	for <nat-archive@odin.ietf.org>; Fri, 15 Sep 2000 00:58:47 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id VAA09402;
	Thu, 14 Sep 2000 21:48:47 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id VAA26783
	for nat-outgoing; Thu, 14 Sep 2000 21:52:20 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
Message-Id: <4.3.1.2.20000914211753.00c5a7c0@pop3.ipverse.com>
X-Sender: matt@ipverse.com@pop3.ipverse.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.1
Date: Thu, 14 Sep 2000 21:27:12 -0700
To: "Joris Dobbelsteen" <joris.dobbelsteen@mail.com>
From: Matt Holdrege <matt@ipverse.com>
Subject: RE: (NAT) IPv6 and NAT
Cc: "IPng WG (E-mail)" <ipng@sunroof.eng.sun.com>,
        "NAT WG (E-mail)" <nat@livingston.com>
In-Reply-To: <001101c01e7e$f23a6640$0d0aa8c0@THUIS.LOCAL>
References: <Pine.GSO.3.96.1000913180234.11779D-100000@da1server>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: Matt Holdrege <matt@ipverse.com>

Joris,

I'm not sure what your point is, but these email lists are solely for the 
purpose of progressing the drafts of the NAT and IPNG working groups 
respectively. If you have a comment on how you would change any outstanding 
Internet Drafts, please let us know what those changes might be.

Specifically, it isn't (IMHO) useful to have discussions here about how you 
assume people use NAT at home. I'm sure there is a better place outside the 
IETF for such discussions.


At 08:56 PM 9/14/00 +0200, Joris Dobbelsteen wrote:
>I've read the drafts about NAT (finally),
>
>As Dan said, NAT will be used, what is not a problem if it's only - AND
>ONLY - used by home users that want to route there network to the Internet
>and have a simple (free) Internet account, that only provides one
>public/Internet IP address to them.
>
>Let's assume MOST (not all) home users won't make much use from all the
>security services that are provides, like IPSec (SSL, etc. with e.g. HTTPS
>is not a problem). They also don't have complex networks and only want to be
>able to use a web browser, send/receive e-mail and play a game on the
>Internet. Most of these services can be done over NAT, usually home users
>have only one network link, and a quite simple network.
>Actually, I like it on a home LAN, even with it's limitations....
>
>For better explanation, I mean with a Home LAN a network consisting of a
>single link with no routers, and (maybe) only one NAT router to the
>Internet.
>
>Businesses usually have more complex networks, require security services and
>things that don't work with NAT. For them NAT should be highly discouraged.
>
>However now the problem that arises, most computers will not be equipped
>with two network cards, where one is for the private network, and the other
>one for the Internet.
>Hope you understand what I mean???? Let me explain a bit better before you
>give comment (most likely needed)...
>
>
>Let's take the Microsoft Windows platform for example (e.g. Windows 98).
>This is the only platform where I have experience with IPv4 transports.
>
>Your computer is connected to a private network and has a private IP
>address. So why not add the public IP address to the same adapter to be used
>for the Internet connection?
>Well, Windows doesn't assign services (like file and printer sharing) to IP
>address, but to the Network adapter itself, regardless of any network
>protocol and it's configuration. This will mean everybody on the private
>network AND the Internet will access your computer using the MS File and
>Printer Sharing! This is only one service where the problem arises...
>
>And why can't we install an additional Network Adapter?
>This solution is not cost-efficient: It will require around $100 for every
>computer that needs a connection to the Internet, and not counting the cost
>for the UTP hubs needed.
>
>
>The solution to this problem is probably VPN, (IP-over-IP) tunneling or
>something similar. Maybe there are other solutions, but I'm not familiar
>with them or don't know of there existence.
>Maybe that software implementers can provide a virtual device driver that
>simulates a network adapter connected to the Internet and has IP tunneling.
>But I leave this discussion to the software implementers.
>
>
>Before I forget, some of you talked about Interface-local, link-local and
>site-local IPv6 address, but these cannot be used on the Internet, nor
>routed to the Internet without the translation that is subjected to retire
>after IPv6 (just like the private IPv4 addresses).
>
>
>
>
>- Joris
>
>
>
> > -----Original Message-----
> > From: owner-ipng@sunroof.eng.sun.com
> > [mailto:owner-ipng@sunroof.eng.sun.com]On Behalf Of Greg Maxwell
> > Sent: donderdag 14 september 2000 0:32
> > To: Dan Lanciani
> > Cc: ipng@sunroof.eng.sun.com
> > Subject: Re: (NAT) IPv6 and NAT
> >
> >
> > On Wed, 13 Sep 2000, Dan Lanciani wrote:
> >
> > [snip]
> > > discourage them from consuming it all.  Offer the v6 space
> > on the terms that v4
> > > space was once available (i.e., free with nominal
> > justification documentation)
> > > and I'm sure people will use it.
> > [snip]
> > > The same argument applies to NAT.  If ISPs make it
> > expensive to get extra v6
> > > addresses (based on the justification that addresses used
> > to be scarce?) then
> > > people will use NAT with IPv6.  If ISPs make "stable" v6
> > addresses (i.e., ones
> > > that they do not deliberately renumber frequently) a
> > premium service then
> > > people will use NAT.
> >
> > Simple. Require that any group providing packet transport services (an
> > ISP) to provide address space to their users under the same set of
> > qualifications required for the provider to obtain address space at a
> > maximum.
> >
> > This would be enforced by making compliance mandatory for
> > address space
> > allocations (thus making the requirement recursive (i.e users
> > of user of
> > users).
> >
> > This would not effect a providers ability to otherwise sell transport
> > services under whatever contract their customers and they agree opon.
> >
> > It would also simplify justification documentation for providers, just
> > concatenate their user's justification documents with their
> > own to form
> > their application.
> >
> > I believe this is the only way to break the idea that network
> > addresses
> > are a valuable commodity and to prevent NAT.
> >
> > > Although the standard claim is that NAT breaks the end-
> > > to-end model we all like (and note that I have personally
> > never liked NAT),
> > > NAT shines at preserving the stable-address model that is
> > deeply embedded in
> > > many protocols and applications.  NAT has already proved
> > itself:  many useful
> > > applications work just fine in spite of the loss of the
> > end-to-end model.
> >
> > NAT is abominable. It subtlety breaks things and hides the
> > cause. It is
> > full of exceptions and gotchas.
> >
> > One layer of NAT can be manageable when the network is small
> > and has only
> > a single outside path.
> >
> > However, as networks become large and better innerconnected, peering
> > address conflicts on NATed networks necessitate multiple layers of NAT
> > causing a complicated 'WHO's on first?' situation. Furthermore, the
> > statefulness required by many->one NAT (and one-one for some
> > protocols)
> > makes many types of highly-available configuration virtually
> > impossible to
> > achieve. Indeed, virtually all NAT solutions force there to
> > be a single
> > point of failure or a single site of failure.
> >
> > NAT is a descent into madness.
> >
> > > I happen to think that ISPs will charge a premium for
> > multiple and/or stable
> > > v6 addresses because that is the status quo and because the
> > market will bear
> > > it.
> >
> > I agree unless they are required not to practice this harmful
> > activity.
> >
> > The legally required goal of a corporation is to maxmize shareholder
> > profits. This goal may at times conflict with the goal of providing a
> > global, scalable, available, and optimally useful network
> > infrastructure.
> >
> > Indeed, a heavily NATed internet enviroment would create many
> > additional
> > network contracting and consulting jobs.
> >
> > > Thus, I suspect that NAT will remain quite active if/when
> > IPv6 is deployed.
> >
> > If it does IPv6 will fail.
> > An IPv6 NATatopia would offer no benifit to consumers or
> > providers over an
> > IPv4 NATatopia.
> >
> > > I think this is unfortunate--again, I'm no fan of NAT--but
> > it's probably too
> > > late to do anything.  While it certainly would have been
> > possible to structure
> > > IPv6 in such a way that end users could allocate identity
> > addresses independent
> > [snip]
> >
> > > So the market pressures will continue to operate in an IPv6
> > environment just as
> > > they have in the IPv4 one.  All IMHO, of course...
> >
> > I think the solution is obvious: If a detrimental behavior is expected
> > then simply forbid it.
> >
> > There is no point to being wishey-washey. Progress is not made by
> > the mediocre.
> >
> > Gregory Maxwell
> >
> > --
> > The comments and opinions expressed herein are those of the
> > author of this
> > message and may not reflect the policies of the Martin County Board of
> > County Commissioners.
> >
> >
> > --------------------------------------------------------------------
> > IETF IPng Working Group Mailing List
> > IPng Home Page:                      http://playground.sun.com/ipng
> > FTP archive:                      ftp://playground.sun.com/pub/ipng
> > Direct all administrative requests to majordomo@sunroof.eng.sun.com
> > --------------------------------------------------------------------
> >
>
>-
>To unsubscribe, email 'majordomo@livingston.com' with
>'unsubscribe nat' in the body of the message.

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@livingston.com  Thu Sep 21 09:10:54 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id JAA05145
	for <nat-archive@odin.ietf.org>; Thu, 21 Sep 2000 09:10:54 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id FAA22029;
	Thu, 21 Sep 2000 05:59:55 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id FAA23202
	for nat-outgoing; Thu, 21 Sep 2000 05:57:49 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
From: Darren Reed <darrenr@reed.wattle.id.au>
Message-Id: <200009211256.XAA17954@avalon.reed.wattle.id.au>
Subject: (NAT) headaches with NAT and patents.
To: nat@livingston.com
Date: Thu, 21 Sep 2000 23:56:47 +1100 (EST)
X-Mailer: ELM [version 2.4ME+ PL37 (25)]
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: Darren Reed <darrenr@reed.wattle.id.au>
Content-Transfer-Encoding: 7bit


In recent days, someone has made me aware of a patent by Cisco on NAT,
#5793763.  Someone pointed me to a NATwg web page which referenced IBM
and mentioned they had a patent which was filed before Cisco's.  On top
of this, I've had someone contact me and mention that they did a NAT
implementation in a time frame which would pre-date the filing dates
of both patents.  Is this something which is worth following up with
further, for details, so that the IETF work can be considered "patent
free" ?

btw, having read both the IBM and Cisco patent, is it just me or do
both patents only make a claim for "half" of the process - that of
`restoring' the original destination IP address ?

Darren
-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@livingston.com  Thu Sep 21 15:14:01 2000
Received: from bast.livingston.com (bast.livingston.com [149.198.247.2])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id PAA12703
	for <nat-archive@odin.ietf.org>; Thu, 21 Sep 2000 15:14:00 -0400 (EDT)
Received: from server.livingston.com (server.livingston.com [149.198.1.70])
	by bast.livingston.com (8.9.3/8.9.3) with ESMTP id LAA27155;
	Thu, 21 Sep 2000 11:58:59 -0700 (PDT)
Received: (from majordom@localhost)
	by server.livingston.com (8.9.3/8.9.3/1.0) id LAA15085
	for nat-outgoing; Thu, 21 Sep 2000 11:59:23 -0700 (PDT)
X-Authentication-Warning: server.livingston.com: majordom set sender to owner-nat@livingston.com using -f
From: Darren Reed <darrenr@reed.wattle.id.au>
Message-Id: <200009211858.FAA18229@avalon.reed.wattle.id.au>
Subject: Re: (NAT) headaches with NAT and patents.
In-Reply-To: <031a01c023e0$abf68440$adfb10ac@francislaptop> from Paul Francis at "Sep 21, 0 08:29:02 am"
To: paul@francis.com
Date: Fri, 22 Sep 2000 05:58:01 +1100 (EST)
Cc: nat@livingston.com
X-Mailer: ELM [version 2.4ME+ PL37 (25)]
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Sender: owner-nat@livingston.com
Precedence: bulk
Reply-To: Darren Reed <darrenr@reed.wattle.id.au>
Content-Transfer-Encoding: 7bit

In some email I received from Paul Francis, sie wrote:
[Charset iso-8859-1 unsupported, filtering to ASCII...]
> 
> > In recent days, someone has made me aware of a patent by Cisco on NAT,
> > #5793763.  Someone pointed me to a NATwg web page which referenced IBM
> > and mentioned they had a patent which was filed before Cisco's.  On top
> > of this, I've had someone contact me and mention that they did a NAT
> > implementation in a time frame which would pre-date the filing dates
> > of both patents.  Is this something which is worth following up with
> 
> What are the filing dates?  (for that matter, do you have a pointer to the
> patent?)

The IBM patent is December 1994 - the URL for this group is
http://www.ietf.org/ietf/IPR/NAT-VRRP-IBM

The Cisco patent was filed November 1995 - number 5793763.

> I gave the first public talk of NAT at the Vancouver IETF (summer 1990), and
> published it in sigcomm CCR around '91-'92.  That publication talked about
> various things including dns tricks, but unfortunately I don't think it
> included port translation.

Do you have pointers to these papers, online, as URLs ?

Darren
-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe nat' in the body of the message.


