Educause Security Discussion mailing list archives
Re: Large edu's doing NAT campus wide?
From: Jeff Murphy <jcmurphy () BUFFALO EDU>
Date: Sun, 29 Apr 2007 10:00:43 -0400
I recall Indiana U presenting on a campus NAT service at the June'03 I2 Tech Update meeting. Here's the presentation: http://www.ncne.org/training/techs/2003/0803/presentations/0803-davy1_files/v3_document.htm slides 16 and 17. IU's implementation was interesting in that they simply changed the first octet to a 10 to make the service easy to deploy (slide 17). So your 'normal' subnet would also have a private subnet overlayed on it where the first octet was a 10. The departments could then selectively deploy devices into either subnet based on the scope of service that the device was offering. I agree that the security aspects are debatable, but it's inline with the conservative nature of security: permit only what's necessary. If a device (LOM, KVM, printers, etc) don't need to be globally accessible, yadda yadda. From an address space conservation perspective, it has obvious benefits and the same logic applies - if a device doesn't need global visibility, then drop it in private space so you can give that address to a device that does need that reachability. Like many U's (I suspect) we use private address space for management console access and for VOIP. We don't offer a NAT service for private address space and haven't offered to route private address space around for departmental use. jeff
Current thread:
- Large edu's doing NAT campus wide? Joe St Sauver (Apr 28)
- <Possible follow-ups>
- Re: Large edu's doing NAT campus wide? Scott O. Bradner (Apr 28)
- Re: Large edu's doing NAT campus wide? Randy Marchany (Apr 28)
- Re: Large edu's doing NAT campus wide? Randall C Grimshaw (Apr 29)
- Re: Large edu's doing NAT campus wide? Jeff Murphy (Apr 29)
- Re: Large edu's doing NAT campus wide? Joe St Sauver (Apr 29)
- Re: Large edu's doing NAT campus wide? Chris Allison (Apr 29)
- Re: Large edu's doing NAT campus wide? Kenneth Arnold (Apr 29)
- Re: Large edu's doing NAT campus wide? Russell Fulton (Apr 29)
- Re: Large edu's doing NAT campus wide? Cal Frye (Apr 29)
- Re: Large edu's doing NAT campus wide? Jeff Kell (Apr 29)
- Large edu's doing NAT campus wide? Marcos Vieyra (Apr 30)
- Re: Large edu's doing NAT campus wide? Clifford Collins (Apr 30)
- Re: Large edu's doing NAT campus wide? Justin Azoff (Apr 30)
- Re: Large edu's doing NAT campus wide? Roger Safian (Apr 30)
(Thread continues...)