Syslog Format for NAT Logging
draft-ietf-behave-syslog-nat-logging-06
| Document | Type | Expired Internet-Draft (individual) | |
|---|---|---|---|
| Authors | Zhonghua Chen , Cathy Zhou , Tina Tsou , Tom Taylor | ||
| Last updated | 2019-06-04 (latest revision 2014-01-24) | ||
| Replaces | draft-zhou-behave-syslog-nat-logging | ||
| Stream | Internet Engineering Task Force (IETF) | ||
| Intended RFC status | Proposed Standard | ||
| Formats |
Expired & archived
pdf
htmlized (tools)
htmlized
bibtex
|
||
| Stream | WG state | WG Document | |
| Document shepherd | No shepherd assigned | ||
| IESG | IESG state | Expired (IESG: Dead) | |
| Action Holders |
(None)
|
||
| Consensus Boilerplate | Unknown | ||
| Telechat date | |||
| Responsible AD | Magnus Westerlund | ||
| Send notices to | (None) | ||
https://www.ietf.org/archive/id/draft-ietf-behave-syslog-nat-logging-06.txt
Abstract
NAT devices are required to log events like creation and deletion of translations and information about the resources the NAT is managing. The logs are required to identify an attacker or a host that was used to launch malicious attacks, and for various other purposes of accounting and management. Since there is no standard way of logging this information, different NAT devices behave differently. The lack of a consistent way makes it difficult to write the collector applications that would receive this data and process it to present useful information. This document describes the information that is required to be logged by the NAT devices. It goes on to standardize formats for reporting these events and parameters using SYSLOG (RFC 5424). A companion document specifies formats for reporting the same events and parameters using IPFIX (RFC 7011). Applicability statements are provided in this document and its companion to guide operators and implementors in their choice of which technology to use for logging.
Authors
Zhonghua Chen
(18918588897@189.cn)
Cathy Zhou
(cathy.zhou@huawei.com)
Tina Tsou
(tina.tsou.zouting@huawei.com)
Tom Taylor
(tom.taylor.stds@gmail.com)
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)