From owner-nat@portmasters.com  Sun Dec 10 02:33:15 2000
Received: from linux2.portmasters.com (root@[12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id CAA26921
	for <nat-archive@odin.ietf.org>; Sun, 10 Dec 2000 02:33:14 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBA7JLH09702
	for nat-outgoing; Sun, 10 Dec 2000 01:19:21 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
To: nat@livingston.com
Date: Sun, 10 Dec 2000 12:46:59 +0530
From: "revati mariappan" <mmanju@lycos.com>
Message-ID: <OHJOAACHPHDGCAAA@mailcity.com>
Mime-Version: 1.0
X-Sent-Mail: on
X-Mailer: MailCity Service
Subject: (NAT) NAT frag
X-Sender-Ip: 202.144.64.4
Organization: Lycos Communications  (http://comm.lycos.com:80)
Content-Type: text/plain; charset=us-ascii
Content-Language: en
Content-Transfer-Encoding: 7bit
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: "revati mariappan" <mmanju@lycos.com>
Content-Transfer-Encoding: 7bit

hi,

is there any way to support fragmentation with NAPT

manju




Get FREE Email/Voicemail with 15MB at Lycos Communications at http://comm.lycos.com
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Mon Dec 11 20:19:13 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id UAA21219
	for <nat-archive@odin.ietf.org>; Mon, 11 Dec 2000 20:19:12 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBC1EGs04894
	for nat-outgoing; Mon, 11 Dec 2000 19:14:16 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-ID: <20001212013234.18213.qmail@web1405.mail.yahoo.com>
Date: Mon, 11 Dec 2000 17:32:34 -0800 (PST)
From: Pyda Srisuresh <srisuresh@yahoo.com>
Subject: Re: (NAT) NAT frag
To: revati mariappan <mmanju@lycos.com>, nat@livingston.com
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Pyda Srisuresh <srisuresh@yahoo.com>


--- revati mariappan <mmanju@lycos.com> wrote:
> hi,
> 
> is there any way to support fragmentation with NAPT
> 
> manju

Here is what the Traditional-NAT draft says about fragmentation 
with NAPT.

6.3. Translation of outbound TCP/UDP fragmented packets in NAPT setup

   Translation of outbound TCP/UDP fragments (i.e., those originating
   from private hosts) in NAPT setup are doomed to fail. The reason is 
   as follows. Only the first fragment contains the TCP/UDP header that 
   would be necessary to associate the packet to a session for 
   translation purposes. Subsequent fragments do not contain TCP/UDP 
   port information, but simply carry the same fragmentation identifier 
   specified in the first fragment. Say, two private hosts originated
   fragmented TCP/UDP packets to the same destination host.  And, they
   happened to use the same fragmentation identifier. When the
   target host receives the two unrelated datagrams, carrying same 
   fragmentation id, and from the same assigned host address, it 
   is unable to determine which of the two sessions the datagrams 
   belong to. Consequently, both sessions will be corrupted.



cheers,
suresh


__________________________________________________
Do You Yahoo!?
Yahoo! Shopping - Thousands of Stores. Millions of Products.
http://shopping.yahoo.com/
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Tue Dec 12 00:13:09 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id AAA09563
	for <nat-archive@odin.ietf.org>; Tue, 12 Dec 2000 00:13:08 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBC5AAa09163
	for nat-outgoing; Mon, 11 Dec 2000 23:10:10 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-ID: <3A35B1F4.40AFA372@cisco.com>
Date: Tue, 12 Dec 2000 10:34:52 +0530
From: Rohit <rrohit@cisco.com>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: nat@portmasters.com
CC: raz@lucent.com
Subject: (NAT) SNMP application layer gateway
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Rohit <rrohit@cisco.com>
Content-Transfer-Encoding: 7bit

Hi, 

  One of our customer is asking us for the support of 
  SNMP application layer gateway on CISCO router.

  RFC2962 covers most of the aspect of the SNMP ALG.
   
  As we don't want to use router resources for SNMP ALG 
  then according to RFC2962  it can be a separate entity, that may
  reside on a separate node.

  But we are planning for an alternate solution where we will
  define an NAT-MIB which will define the NAT Translation Table.
  The Management station will query the NAT-MIB and perform the
  address translation at the management station itself.

  We believe that it should solve the payload translation problem
  (which ALG would have done otherwise). It would be nice if
  someone from this alias could comment on the same.

  Thanks
  Rohit
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Tue Dec 12 02:40:45 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id CAA03190
	for <nat-archive@odin.ietf.org>; Tue, 12 Dec 2000 02:40:44 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBC7Y6S11866
	for nat-outgoing; Tue, 12 Dec 2000 01:34:06 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-ID: <91CDB24C5FCDD31198A2009027E79021011BD72B@exchange.2wire.com>
From: Randy Turner <rturner@2wire.com>
To: "'Rohit '" <rrohit@cisco.com>,
        "'nat@portmasters.com '"
	 <nat@portmasters.com>
Cc: "'raz@lucent.com '" <raz@lucent.com>
Subject: RE: (NAT) SNMP application layer gateway
Date: Mon, 11 Dec 2000 23:41:13 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Content-Type: text/plain;
	charset="iso-8859-1"
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Randy Turner <rturner@2wire.com>

 
Obviously, this cannot be a generic SNMP management station, because
management stations just don't do this kind of thing.  I haven't been
following the MIB standardization process very closely, but I'm assuming
that someone is working on  a "standard" NAT MIB? I would think you would
need the ALG support anyway. It would cover far more cases than a management
station approach.

Randy

-----Original Message-----
From: Rohit
To: nat@portmasters.com
Cc: raz@lucent.com
Sent: 12/11/00 9:04 PM
Subject: (NAT) SNMP application layer gateway

Hi, 

  One of our customer is asking us for the support of 
  SNMP application layer gateway on CISCO router.

  RFC2962 covers most of the aspect of the SNMP ALG.
   
  As we don't want to use router resources for SNMP ALG 
  then according to RFC2962  it can be a separate entity, that may
  reside on a separate node.

  But we are planning for an alternate solution where we will
  define an NAT-MIB which will define the NAT Translation Table.
  The Management station will query the NAT-MIB and perform the
  address translation at the management station itself.

  We believe that it should solve the payload translation problem
  (which ALG would have done otherwise). It would be nice if
  someone from this alias could comment on the same.

  Thanks
  Rohit
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Tue Dec 12 03:15:34 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id DAA13985
	for <nat-archive@odin.ietf.org>; Tue, 12 Dec 2000 03:15:33 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBC8DeW12515
	for nat-outgoing; Tue, 12 Dec 2000 02:13:40 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-ID: <3A35DCEF.ED1BE815@cisco.com>
Date: Tue, 12 Dec 2000 13:38:15 +0530
From: Rohit <rrohit@cisco.com>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: Randy Turner <rturner@2wire.com>
CC: "'nat@portmasters.com '" <nat@portmasters.com>,
        "'raz@lucent.com '" <raz@lucent.com>
Subject: Re: (NAT) SNMP application layer gateway
References: <91CDB24C5FCDD31198A2009027E79021011BD72B@exchange.2wire.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Rohit <rrohit@cisco.com>
Content-Transfer-Encoding: 7bit

Hi Randy, 

  I do agree that on the SNMP Management station side we need
  to have an extra layer performing the NAT specific stuff.
  If anyone is already working on the "standard" NAT MIB , that
  will be great for us otherwise we will have to define the MIB.
  If we can provide this type of extra support on the management station
  side why do we need ALG support. Anyway we do support proxy according
to 
  RFC2573.

  Thanks
  Rohit

Randy Turner wrote:
> 
> 
> Obviously, this cannot be a generic SNMP management station, because
> management stations just don't do this kind of thing.  I haven't been
> following the MIB standardization process very closely, but I'm assuming
> that someone is working on  a "standard" NAT MIB? I would think you would
> need the ALG support anyway. It would cover far more cases than a management
> station approach.
> 
> Randy
> 
> -----Original Message-----
> From: Rohit
> To: nat@portmasters.com
> Cc: raz@lucent.com
> Sent: 12/11/00 9:04 PM
> Subject: (NAT) SNMP application layer gateway
> 
> Hi,
> 
>   One of our customer is asking us for the support of
>   SNMP application layer gateway on CISCO router.
> 
>   RFC2962 covers most of the aspect of the SNMP ALG.
> 
>   As we don't want to use router resources for SNMP ALG
>   then according to RFC2962  it can be a separate entity, that may
>   reside on a separate node.
> 
>   But we are planning for an alternate solution where we will
>   define an NAT-MIB which will define the NAT Translation Table.
>   The Management station will query the NAT-MIB and perform the
>   address translation at the management station itself.
> 
>   We believe that it should solve the payload translation problem
>   (which ALG would have done otherwise). It would be nice if
>   someone from this alias could comment on the same.
> 
>   Thanks
>   Rohit
> -
> To unsubscribe, email 'majordomo@portmasters.com' with
> 'unsubscribe nat' in the body of the message.
> -
> To unsubscribe, email 'majordomo@portmasters.com' with
> 'unsubscribe nat' in the body of the message.
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Tue Dec 12 09:44:00 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id JAA03109
	for <nat-archive@odin.ietf.org>; Tue, 12 Dec 2000 09:43:59 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBCEVZJ16656
	for nat-outgoing; Tue, 12 Dec 2000 08:31:35 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-Id: <4.1.20001212092541.00cd94f0@smtp.cmh.ascend.com>
X-Sender: mhandler@smtp.cmh.ascend.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.1 
Date: Tue, 12 Dec 2000 09:27:48 -0500
To: Pyda Srisuresh <srisuresh@yahoo.com>
From: Mike Handler <mikehandler@lucent.com>
Subject: Re: (NAT) NAT frag
Cc: revati mariappan <mmanju@lycos.com>, nat@livingston.com
In-Reply-To: <20001212013234.18213.qmail@web1405.mail.yahoo.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Mike Handler <mikehandler@lucent.com>

A NAT implementer can implement around it, though, by defragmenting 
before NATting, or by translating fragmentation identifiers as well.

MH

At 08:32 PM 12/11/2000 , Pyda Srisuresh wrote:
>
>--- revati mariappan <mmanju@lycos.com> wrote:
>> hi,
>> 
>> is there any way to support fragmentation with NAPT
>> 
>> manju
>
>Here is what the Traditional-NAT draft says about fragmentation 
>with NAPT.
>
>6.3. Translation of outbound TCP/UDP fragmented packets in NAPT setup
>
>   Translation of outbound TCP/UDP fragments (i.e., those originating
>   from private hosts) in NAPT setup are doomed to fail. The reason is 
>   as follows. Only the first fragment contains the TCP/UDP header that 
>   would be necessary to associate the packet to a session for 
>   translation purposes. Subsequent fragments do not contain TCP/UDP 
>   port information, but simply carry the same fragmentation identifier 
>   specified in the first fragment. Say, two private hosts originated
>   fragmented TCP/UDP packets to the same destination host.  And, they
>   happened to use the same fragmentation identifier. When the
>   target host receives the two unrelated datagrams, carrying same 
>   fragmentation id, and from the same assigned host address, it 
>   is unable to determine which of the two sessions the datagrams 
>   belong to. Consequently, both sessions will be corrupted.
>
>
>
>cheers,
>suresh
>
>
>__________________________________________________
>Do You Yahoo!?
>Yahoo! Shopping - Thousands of Stores. Millions of Products.
>http://shopping.yahoo.com/
>-
>To unsubscribe, email 'majordomo@portmasters.com' with
>'unsubscribe nat' in the body of the message.

-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Tue Dec 12 16:57:25 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id QAA18898
	for <nat-archive@odin.ietf.org>; Tue, 12 Dec 2000 16:57:24 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBCLsIE24893
	for nat-outgoing; Tue, 12 Dec 2000 15:54:18 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Date: Tue, 12 Dec 2000 22:51:49 +0100
Message-Id: <200012122151.WAA11789@henkell.ibr.cs.tu-bs.de>
From: Juergen Schoenwaelder <schoenw@ibr.cs.tu-bs.de>
To: rrohit@cisco.com
CC: rturner@2wire.com, nat@portmasters.com, raz@lucent.com
In-reply-to: <3A35DCEF.ED1BE815@cisco.com> (message from Rohit on Tue, 12 Dec
	2000 13:38:15 +0530)
Subject: Re: (NAT) SNMP application layer gateway
References: <91CDB24C5FCDD31198A2009027E79021011BD72B@exchange.2wire.com> <3A35DCEF.ED1BE815@cisco.com>
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Juergen Schoenwaelder <schoenw@ibr.cs.tu-bs.de>


>>>>> Rohit  writes:

Rohit> I do agree that on the SNMP Management station side we need
Rohit> to have an extra layer performing the NAT specific stuff.

You are basically putting the NAT into the management station if I
understand correctly.

Rohit> If anyone is already working on the "standard" NAT MIB , that
Rohit> will be great for us otherwise we will have to define the MIB.
Rohit> If we can provide this type of extra support on the management
Rohit> station side why do we need ALG support. Anyway we do support
Rohit> proxy according to RFC2573.

So why do you not just use proxies?

/js

-- 
Juergen Schoenwaelder      Technical University Braunschweig
<schoenw@ibr.cs.tu-bs.de>  Dept. Operating Systems & Computer Networks
Phone: +49 531 391 3289    Bueltenweg 74/75, 38106 Braunschweig, Germany
Fax:   +49 531 391 5936    <URL:http://www.ibr.cs.tu-bs.de/~schoenw/>
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Tue Dec 12 17:30:58 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id RAA26042
	for <nat-archive@odin.ietf.org>; Tue, 12 Dec 2000 17:30:58 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBCMSS625573
	for nat-outgoing; Tue, 12 Dec 2000 16:28:28 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-ID: <20001212224807.12267.qmail@web1405.mail.yahoo.com>
Date: Tue, 12 Dec 2000 14:48:07 -0800 (PST)
From: Pyda Srisuresh <srisuresh@yahoo.com>
Subject: RE: (NAT) SNMP application layer gateway
To: Randy Turner <rturner@2wire.com>, "'Rohit '" <rrohit@cisco.com>,
        "'nat@portmasters.com '" <nat@portmasters.com>
Cc: "'raz@lucent.com '" <raz@lucent.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Pyda Srisuresh <srisuresh@yahoo.com>

Randy and Rohit,

Please see my comments below.

cheers,
suresh

--- Randy Turner <rturner@2wire.com> wrote:
>  
> Obviously, this cannot be a generic SNMP management station, because
> management stations just don't do this kind of thing.  I haven't been
> following the MIB standardization process very closely, but I'm assuming
> that someone is working on  a "standard" NAT MIB? I would think you would
> need the ALG support anyway. It would cover far more cases than a management
> station approach.

No one is working on a "standard NAT MIB", as far as I know. I.e., we dont
have a draft yet. In the event of a NAT MIB becoming available, I dont
see why that has any dependency on SNMP-ALG support. As far as I can tell,
NAT MIB and SNMP-ALG are orthogonal issues. 

> 
> Randy
> 
> -----Original Message-----
> From: Rohit
> To: nat@portmasters.com
> Cc: raz@lucent.com
> Sent: 12/11/00 9:04 PM
> Subject: (NAT) SNMP application layer gateway
> 
> Hi, 
> 
>   One of our customer is asking us for the support of 
>   SNMP application layer gateway on CISCO router.
> 
>   RFC2962 covers most of the aspect of the SNMP ALG.
>    
>   As we don't want to use router resources for SNMP ALG 
>   then according to RFC2962  it can be a separate entity, that may
>   reside on a separate node.
> 

Thus far, I understand what you say.

>   But we are planning for an alternate solution where we will
>   define an NAT-MIB which will define the NAT Translation Table.
>   The Management station will query the NAT-MIB and perform the
>   address translation at the management station itself.
> 
That sounds fine as well. Are the address maps static or dynamic?
You may have a problem with dynamic maps.

>   We believe that it should solve the payload translation problem
>   (which ALG would have done otherwise). It would be nice if
>   someone from this alias could comment on the same.

If the managment station is doing the translation of the payload,
then the management station has the ALG funtion within it. You are
suggesting that the managment station obtain the translation table
from the NAT router through a MIB.

SO far, I dont see any contradiction in terms with RFC 2962.

> 
>   Thanks
>   Rohit
> 

cheers,
suresh

__________________________________________________
Do You Yahoo!?
Yahoo! Shopping - Thousands of Stores. Millions of Products.
http://shopping.yahoo.com/
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Tue Dec 12 23:48:02 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id XAA02437
	for <nat-archive@odin.ietf.org>; Tue, 12 Dec 2000 23:48:01 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBD4jkh29845
	for nat-outgoing; Tue, 12 Dec 2000 22:45:46 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-ID: <3A36FDB6.CF6A942A@cisco.com>
Date: Wed, 13 Dec 2000 10:10:22 +0530
From: Rohit <rrohit@cisco.com>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: Pyda Srisuresh <srisuresh@yahoo.com>
CC: Randy Turner <rturner@2wire.com>,
        "'nat@portmasters.com '" <nat@portmasters.com>,
        "'raz@lucent.com '" <raz@lucent.com>
Subject: Re: (NAT) SNMP application layer gateway
References: <20001212224807.12267.qmail@web1405.mail.yahoo.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Rohit <rrohit@cisco.com>
Content-Transfer-Encoding: 7bit

Hi, 

  Is it possible that we go ahead with writing a "standard NAT-MIB" and 
  then present our MIB to this alias to be accepted as an draft ?

  Thanks
  Rohit 

Pyda Srisuresh wrote:
> 
> Randy and Rohit,
> 
> Please see my comments below.
> 
> cheers,
> suresh
> 
> --- Randy Turner <rturner@2wire.com> wrote:
> >
> > Obviously, this cannot be a generic SNMP management station, because
> > management stations just don't do this kind of thing.  I haven't been
> > following the MIB standardization process very closely, but I'm assuming
> > that someone is working on  a "standard" NAT MIB? I would think you would
> > need the ALG support anyway. It would cover far more cases than a management
> > station approach.
> 
> No one is working on a "standard NAT MIB", as far as I know. I.e., we dont
> have a draft yet. In the event of a NAT MIB becoming available, I dont
> see why that has any dependency on SNMP-ALG support. As far as I can tell,
> NAT MIB and SNMP-ALG are orthogonal issues.
> 
> >
> > Randy
> >
> > -----Original Message-----
> > From: Rohit
> > To: nat@portmasters.com
> > Cc: raz@lucent.com
> > Sent: 12/11/00 9:04 PM
> > Subject: (NAT) SNMP application layer gateway
> >
> > Hi,
> >
> >   One of our customer is asking us for the support of
> >   SNMP application layer gateway on CISCO router.
> >
> >   RFC2962 covers most of the aspect of the SNMP ALG.
> >
> >   As we don't want to use router resources for SNMP ALG
> >   then according to RFC2962  it can be a separate entity, that may
> >   reside on a separate node.
> >
> 
> Thus far, I understand what you say.
> 
> >   But we are planning for an alternate solution where we will
> >   define an NAT-MIB which will define the NAT Translation Table.
> >   The Management station will query the NAT-MIB and perform the
> >   address translation at the management station itself.
> >
> That sounds fine as well. Are the address maps static or dynamic?
> You may have a problem with dynamic maps.
> 
> >   We believe that it should solve the payload translation problem
> >   (which ALG would have done otherwise). It would be nice if
> >   someone from this alias could comment on the same.
> 
> If the managment station is doing the translation of the payload,
> then the management station has the ALG funtion within it. You are
> suggesting that the managment station obtain the translation table
> from the NAT router through a MIB.
> 
> SO far, I dont see any contradiction in terms with RFC 2962.
> 
> >
> >   Thanks
> >   Rohit
> >
> 
> cheers,
> suresh
> 
> __________________________________________________
> Do You Yahoo!?
> Yahoo! Shopping - Thousands of Stores. Millions of Products.
> http://shopping.yahoo.com/
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Wed Dec 13 00:17:44 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id XAA02435
	for <nat-archive@odin.ietf.org>; Tue, 12 Dec 2000 23:48:01 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBD4gdv29794
	for nat-outgoing; Tue, 12 Dec 2000 22:42:39 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-ID: <3A36FCF8.DA1B9B@cisco.com>
Date: Wed, 13 Dec 2000 10:07:12 +0530
From: Rohit <rrohit@cisco.com>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: Juergen Schoenwaelder <schoenw@ibr.cs.tu-bs.de>
CC: rturner@2wire.com, nat@portmasters.com, raz@lucent.com
Subject: Re: (NAT) SNMP application layer gateway
References: <91CDB24C5FCDD31198A2009027E79021011BD72B@exchange.2wire.com> <3A35DCEF.ED1BE815@cisco.com> <200012122151.WAA11789@henkell.ibr.cs.tu-bs.de>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Rohit <rrohit@cisco.com>
Content-Transfer-Encoding: 7bit

Hi, 

Juergen Schoenwaelder wrote:
> 
> >>>>> Rohit  writes:
> 
> Rohit> I do agree that on the SNMP Management station side we need
> Rohit> to have an extra layer performing the NAT specific stuff.
> 
> You are basically putting the NAT into the management station if I
> understand correctly.

  Yes , we are planning to do so.

> 
> Rohit> If anyone is already working on the "standard" NAT MIB , that
> Rohit> will be great for us otherwise we will have to define the MIB.
> Rohit> If we can provide this type of extra support on the management
> Rohit> station side why do we need ALG support. Anyway we do support
> Rohit> proxy according to RFC2573.
> 
> So why do you not just use proxies?
> 

  Proxy Forwarder will just forward the SNMP request, it won't translate
the conflicting 
  IP addresses.

  Thanks
  Rohit 
    

> /js
> 
> --
> Juergen Schoenwaelder      Technical University Braunschweig
> <schoenw@ibr.cs.tu-bs.de>  Dept. Operating Systems & Computer Networks
> Phone: +49 531 391 3289    Bueltenweg 74/75, 38106 Braunschweig, Germany
> Fax:   +49 531 391 5936    <URL:http://www.ibr.cs.tu-bs.de/~schoenw/>
> -
> To unsubscribe, email 'majordomo@portmasters.com' with
> 'unsubscribe nat' in the body of the message.
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Wed Dec 13 13:45:16 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id NAA29516
	for <nat-archive@odin.ietf.org>; Wed, 13 Dec 2000 13:45:15 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBDISkk05376
	for nat-outgoing; Wed, 13 Dec 2000 12:28:46 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-Id: <5.0.2.1.2.20001213102254.01ebcc80@pop3.ipverse.com>
X-Sender: matt@ipverse.com@pop3.ipverse.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Wed, 13 Dec 2000 10:25:54 -0800
To: rrohit@cisco.com
From: Matt Holdrege <matt@ipverse.com>
Subject: Re: (NAT) SNMP application layer gateway
Cc: nat@portmasters.com
In-Reply-To: <3A36FDB6.CF6A942A@cisco.com>
References: <20001212224807.12267.qmail@web1405.mail.yahoo.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Matt Holdrege <matt@ipverse.com>

At 08:40 PM 12/12/2000, Rohit wrote:
>Hi,
>
>   Is it possible that we go ahead with writing a "standard NAT-MIB" and
>   then present our MIB to this alias to be accepted as an draft ?

Such an effort would be very welcome. Understand that once a draft is 
accepted as a working group item it will be subject to the wishes of the 
working group. If you haven't written an IETF MIB before, I recommend 
looking at some of the recent MIB RFC's to understand the style.

-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Wed Dec 13 14:41:37 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id OAA09478
	for <nat-archive@odin.ietf.org>; Wed, 13 Dec 2000 14:41:36 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBDJKB006110
	for nat-outgoing; Wed, 13 Dec 2000 13:20:11 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Date: Wed, 13 Dec 2000 20:17:34 +0100
Message-Id: <200012131917.UAA13316@henkell.ibr.cs.tu-bs.de>
From: Juergen Schoenwaelder <schoenw@ibr.cs.tu-bs.de>
To: rrohit@cisco.com
CC: rturner@2wire.com, nat@portmasters.com, raz@lucent.com
In-reply-to: <3A36FCF8.DA1B9B@cisco.com> (message from Rohit on Wed, 13 Dec
	2000 10:07:12 +0530)
Subject: Re: (NAT) SNMP application layer gateway
References: <91CDB24C5FCDD31198A2009027E79021011BD72B@exchange.2wire.com> <3A35DCEF.ED1BE815@cisco.com> <200012122151.WAA11789@henkell.ibr.cs.tu-bs.de> <3A36FCF8.DA1B9B@cisco.com>
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Juergen Schoenwaelder <schoenw@ibr.cs.tu-bs.de>


>>>>> Rohit  writes:

Rohit> Proxy Forwarder will just forward the SNMP request, it won't
Rohit> translate the conflicting IP addresses.

Yes, the management application needs to understand the
situation. Note that an SNMP ALG will only be able to do some
translation and thus it does not really provide a transparent view for
the management application either. And an SNMP ALG has the potential
to screw up SNMP protocol semantics...

/js

-- 
Juergen Schoenwaelder      Technical University Braunschweig
<schoenw@ibr.cs.tu-bs.de>  Dept. Operating Systems & Computer Networks
Phone: +49 531 391 3289    Bueltenweg 74/75, 38106 Braunschweig, Germany
Fax:   +49 531 391 5936    <URL:http://www.ibr.cs.tu-bs.de/~schoenw/>


-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Wed Dec 13 15:03:29 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id PAA12048
	for <nat-archive@odin.ietf.org>; Wed, 13 Dec 2000 15:03:28 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBDK0sZ06740
	for nat-outgoing; Wed, 13 Dec 2000 14:00:54 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-ID: <20001213202109.1826.qmail@web1405.mail.yahoo.com>
Date: Wed, 13 Dec 2000 12:21:09 -0800 (PST)
From: Pyda Srisuresh <srisuresh@yahoo.com>
Subject: Re: (NAT) SNMP application layer gateway
To: Rohit <rrohit@cisco.com>
Cc: Randy Turner <rturner@2wire.com>,
        "'nat@portmasters.com '" <nat@portmasters.com>,
        "'raz@lucent.com '" <raz@lucent.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Pyda Srisuresh <srisuresh@yahoo.com>


--- Rohit <rrohit@cisco.com> wrote:
> Hi, 
> 
>   Is it possible that we go ahead with writing a "standard NAT-MIB" and 
>   then present our MIB to this alias to be accepted as an draft ?
> 
>   Thanks
>   Rohit 

Yes. We will be glad to accept that as a work group item. Thanks.

cheers,
suresh

__________________________________________________
Do You Yahoo!?
Yahoo! Shopping - Thousands of Stores. Millions of Products.
http://shopping.yahoo.com/
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Wed Dec 13 15:34:16 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id PAA17938
	for <nat-archive@odin.ietf.org>; Wed, 13 Dec 2000 15:34:15 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBDKCbU06920
	for nat-outgoing; Wed, 13 Dec 2000 14:12:37 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-ID: <91CDB24C5FCDD31198A2009027E79021011BD73E@exchange.2wire.com>
From: Randy Turner <rturner@2wire.com>
To: "'Pyda Srisuresh '" <srisuresh@yahoo.com>, "'Rohit '" <rrohit@cisco.com>
Cc: Randy Turner <rturner@2wire.com>,
        "''nat@portmasters.com ' '"
	 <nat@portmasters.com>,
        "''raz@lucent.com ' '" <raz@lucent.com>
Subject: RE: (NAT) SNMP application layer gateway
Date: Wed, 13 Dec 2000 12:19:35 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Content-Type: text/plain;
	charset="iso-8859-1"
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: Randy Turner <rturner@2wire.com>

 
Just FYI,

There are folks from Cisco that may have already come up with what would be
a baseline text for such a standard NAT MIB. It's currently a proposal
before the DSL Forum for automatic provisioning of broadband consumer
NAT/router products.

Randy


-----Original Message-----
From: Pyda Srisuresh
To: Rohit
Cc: Randy Turner; 'nat@portmasters.com '; 'raz@lucent.com '
Sent: 12/13/00 12:21 PM
Subject: Re: (NAT) SNMP application layer gateway


--- Rohit <rrohit@cisco.com> wrote:
> Hi, 
> 
>   Is it possible that we go ahead with writing a "standard NAT-MIB"
and 
>   then present our MIB to this alias to be accepted as an draft ?
> 
>   Thanks
>   Rohit 

Yes. We will be glad to accept that as a work group item. Thanks.

cheers,
suresh

__________________________________________________
Do You Yahoo!?
Yahoo! Shopping - Thousands of Stores. Millions of Products.
http://shopping.yahoo.com/
-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Thu Dec 14 02:43:55 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id CAA16422
	for <nat-archive@odin.ietf.org>; Thu, 14 Dec 2000 02:43:54 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBE7Hdk16562
	for nat-outgoing; Thu, 14 Dec 2000 01:17:39 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-ID: <3A386A80.AED571EF@cisco.com>
Date: Thu, 14 Dec 2000 12:36:48 +0600
From: rrohit <rrohit@cisco.com>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: Matt Holdrege <matt@ipverse.com>
CC: nat@portmasters.com
Subject: Re: (NAT) SNMP application layer gateway
References: <20001212224807.12267.qmail@web1405.mail.yahoo.com> <5.0.2.1.2.20001213102254.01ebcc80@pop3.ipverse.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: rrohit <rrohit@cisco.com>
Content-Transfer-Encoding: 7bit

Hi Matt,

 I have written CISCO Specific MIBS in past.
 I will certainly look at some of the recent MIB RFC's to understand the
style.

 Thanks
  Rohit

Matt Holdrege wrote:

> At 08:40 PM 12/12/2000, Rohit wrote:
> >Hi,
> >
> >   Is it possible that we go ahead with writing a "standard NAT-MIB" and
> >   then present our MIB to this alias to be accepted as an draft ?
>
> Such an effort would be very welcome. Understand that once a draft is
> accepted as a working group item it will be subject to the wishes of the
> working group. If you haven't written an IETF MIB before, I recommend
> looking at some of the recent MIB RFC's to understand the style.
>
> -
> To unsubscribe, email 'majordomo@portmasters.com' with
> 'unsubscribe nat' in the body of the message.

-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


From owner-nat@portmasters.com  Thu Dec 14 02:44:26 2000
Received: from linux2.portmasters.com (root@ns2.jakes.org [12.96.1.99])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id CAA16545
	for <nat-archive@odin.ietf.org>; Thu, 14 Dec 2000 02:44:26 -0500 (EST)
Received: (from majordomo@localhost)
	by linux2.portmasters.com (8.11.1/8.11.1) id eBE7FpD16557
	for nat-outgoing; Thu, 14 Dec 2000 01:15:51 -0600
X-Authentication-Warning: linux2.portmasters.com: majordomo set sender to owner-nat@portmasters.com using -f
Message-ID: <3A386A09.FB72F2CB@cisco.com>
Date: Thu, 14 Dec 2000 12:34:50 +0600
From: rrohit <rrohit@cisco.com>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: Randy Turner <rturner@2wire.com>
CC: "'Pyda Srisuresh '" <srisuresh@yahoo.com>,
        "''nat@portmasters.com ' '" <nat@portmasters.com>,
        "''raz@lucent.com ' '" <raz@lucent.com>
Subject: Re: (NAT) SNMP application layer gateway
References: <91CDB24C5FCDD31198A2009027E79021011BD73E@exchange.2wire.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-nat@portmasters.com
Precedence: bulk
Reply-To: rrohit <rrohit@cisco.com>
Content-Transfer-Encoding: 7bit

Hi Randy,

  Thanks for your info.
  I  guess it should be possible to get the baseline text from
  DSL forum for the "standard NAT MIB".

 Thanks
 Rohit

Randy Turner wrote:

>
> Just FYI,
>
> There are folks from Cisco that may have already come up with what would be
> a baseline text for such a standard NAT MIB. It's currently a proposal
> before the DSL Forum for automatic provisioning of broadband consumer
> NAT/router products.
>
> Randy
>
> -----Original Message-----
> From: Pyda Srisuresh
> To: Rohit
> Cc: Randy Turner; 'nat@portmasters.com '; 'raz@lucent.com '
> Sent: 12/13/00 12:21 PM
> Subject: Re: (NAT) SNMP application layer gateway
>
> --- Rohit <rrohit@cisco.com> wrote:
> > Hi,
> >
> >   Is it possible that we go ahead with writing a "standard NAT-MIB"
> and
> >   then present our MIB to this alias to be accepted as an draft ?
> >
> >   Thanks
> >   Rohit
>
> Yes. We will be glad to accept that as a work group item. Thanks.
>
> cheers,
> suresh
>
> __________________________________________________
> Do You Yahoo!?
> Yahoo! Shopping - Thousands of Stores. Millions of Products.
> http://shopping.yahoo.com/
> -
> To unsubscribe, email 'majordomo@portmasters.com' with
> 'unsubscribe nat' in the body of the message.

-
To unsubscribe, email 'majordomo@portmasters.com' with
'unsubscribe nat' in the body of the message.


