nanog mailing list archives
Re: quietly....
From: david raistrick <drais () icantclick org>
Date: Thu, 3 Feb 2011 15:38:47 -0500 (EST)
On Thu, 3 Feb 2011, Valdis.Kletnieks () vt edu wrote:
The only reason FTP works through a NAT is because the NAT has already been hacked up to further mangle the data stream to make up for the mangling it does.
Speaking of should-have-died-years-ago. FTP fits that category well. ;)
I'm told that IPSEC through a NAT can be interesting too... And that's something I'm also told some corporations are interested in.
NAT traversal for ipsec was sorted out more than a few years ago with 3 or 4 different methods in play. I dropped out of that market about the time it came to light, but as a ipsec end user I haven't had NAT problems going back as far as 2006 for sure, possibily further.
(the original problem was that only 1 user behind 1 IP could speak ipsec because it uses a specific protocol, not a port, that can only be 1-to-1. I'll leave it as an exercise for the reader to figure out that was magiced around without requiring the NAT devices to do anything. and ssl doesn't count. :)
-- david raistrick http://www.netmeister.org/news/learn2quote.html drais () icantclick org http://www.expita.com/nomime.html
Current thread:
- Re: quietly...., (continued)
- Re: quietly.... Owen DeLong (Feb 04)
- Re: quietly.... Owen DeLong (Feb 04)
- Re: quietly.... Jack Bates (Feb 05)
- RE: quietly.... Lee Howard (Feb 06)
- Re: quietly.... isabel dias (Feb 06)
- Re: quietly.... Owen DeLong (Feb 06)
- Re: quietly.... Valdis . Kletnieks (Feb 04)
- Re: quietly.... Blake Dunlap (Feb 04)
- Re: quietly.... Jay Ashworth (Feb 04)
- Re: quietly.... Jack Bates (Feb 03)
- Re: quietly.... david raistrick (Feb 03)
- Failure modes: NAT vs SPI Jay Ashworth (Feb 03)
- Re: Failure modes: NAT vs SPI Iljitsch van Beijnum (Feb 03)
- Message not available
- Re: Failure modes: NAT vs SPI Iljitsch van Beijnum (Feb 07)
- Re: Failure modes: NAT vs SPI Owen DeLong (Feb 07)
- Re: Failure modes: NAT vs SPI Lamar Owen (Feb 10)
- Re: Failure modes: NAT vs SPI Owen DeLong (Feb 10)
- Re: Failure modes: NAT vs SPI Joel Jaeggli (Feb 10)
- Re: Failure modes: NAT vs SPI Jay Ashworth (Feb 07)
- Re: Failure modes: NAT vs SPI Valdis . Kletnieks (Feb 07)
- Re: Failure modes: NAT vs SPI Jack Bates (Feb 07)