Skip to main content

IPFIX Information Elements for logging NAT Events
draft-sivakumar-behave-nat-logging-05

The information below is for an old version of the document.
Document Type
This is an older version of an Internet-Draft whose latest revision state is "Replaced".
Expired & archived
Authors Senthil Sivakumar , Reinaldo Penno
Last updated 2013-01-10 (Latest revision 2012-07-09)
Replaced by draft-ietf-behave-ipfix-nat-logging, RFC 8158
RFC stream (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

Carrier grade NAT (CGN) devices are required to log events like creation and deletion of translations and information about the resources it is managing. The logs are required in many cases to identify an attacker or a host that was used to launch malicious attacks and/or for various other purposes of accounting. Since there is no standard way of logging this information, different NAT devices behave differently and hence it is difficult to expect a consistent behavior. The lack of a consistent way makes it difficult to write the collector applications that would receive this data and process it to present useful information. This document describes the information that is required to be logged by the NAT devices.

Authors

Senthil Sivakumar
Reinaldo Penno

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)