Re: [BEHAVE] Port Management To Reduce Logging In Large-Scale NATs

<mohamed.boucadair@orange-ftgroup.com> Mon, 06 September 2010 05:21 UTC

Return-Path: <mohamed.boucadair@orange-ftgroup.com>
X-Original-To: behave@core3.amsl.com
Delivered-To: behave@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id CF2323A6836 for <behave@core3.amsl.com>; Sun, 5 Sep 2010 22:21:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.923
X-Spam-Level:
X-Spam-Status: No, score=-0.923 tagged_above=-999 required=5 tests=[AWL=-1.089, BAYES_40=-0.185, HELO_EQ_FR=0.35, UNPARSEABLE_RELAY=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mKLA5NvHXFyA for <behave@core3.amsl.com>; Sun, 5 Sep 2010 22:21:46 -0700 (PDT)
Received: from relais-inet.francetelecom.com (relais-ias244.francetelecom.com [80.12.204.244]) by core3.amsl.com (Postfix) with ESMTP id EFA063A685C for <behave@ietf.org>; Sun, 5 Sep 2010 22:21:44 -0700 (PDT)
Received: from omfeda05.si.francetelecom.fr (unknown [xx.xx.xx.198]) by omfeda13.si.francetelecom.fr (ESMTP service) with ESMTP id 878B719011A; Mon, 6 Sep 2010 07:22:12 +0200 (CEST)
Received: from PUEXCH61.nanterre.francetelecom.fr (unknown [10.101.44.32]) by omfeda05.si.francetelecom.fr (ESMTP service) with ESMTP id 6E52018003B; Mon, 6 Sep 2010 07:22:12 +0200 (CEST)
Received: from PUEXCB1B.nanterre.francetelecom.fr ([10.101.44.13]) by PUEXCH61.nanterre.francetelecom.fr ([10.101.44.32]) with mapi; Mon, 6 Sep 2010 07:22:12 +0200
From: mohamed.boucadair@orange-ftgroup.com
To: Olivier Vautrin <ovautrin@juniper.net>, Lars Eggert <lars.eggert@nokia.com>
Date: Mon, 06 Sep 2010 07:22:10 +0200
Thread-Topic: [BEHAVE] Port Management To Reduce Logging In Large-Scale NATs
Thread-Index: ActLY4tyA5L9Ux7fST+ebAN8NFmuJAAACoJQAFfc3IAAL7FK8A==
Message-ID: <25053_1283750532_4C847A84_25053_19298_1_94C682931C08B048B7A8645303FDC9F31C501E70A4@PUEXCB1B.nanterre.francetelecom.fr>
References: <979A43C06A7B488B93D6FFBA8395A033@china.huawei.com> <9245BF3C-D02C-4C91-8690-C6261758701A@nokia.com> <17006_1283515801_4C80E599_17006_1679467_1_94C682931C08B048B7A8645303FDC9F31C501E6E33@PUEXCB1B.nanterre.francetelecom.fr> <55DD09BB-C144-4124-8080-332E8B4C0F7B@nokia.com> <26667_1283517256_4C80EB48_26667_79086_1_94C682931C08B048B7A8645303FDC9F31C501E6E60@PUEXCB1B.nanterre.francetelecom.fr> <84600D05C20FF943918238042D7670FD36D96A7BA1@EMBX01-HQ.jnpr.net>
In-Reply-To: <84600D05C20FF943918238042D7670FD36D96A7BA1@EMBX01-HQ.jnpr.net>
Accept-Language: fr-FR
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: fr-FR
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-PMX-Version: 5.5.9.395186, Antispam-Engine: 2.7.2.376379, Antispam-Data: 2010.9.6.42416
Cc: "behave@ietf.org" <behave@ietf.org>, Tina TSOU <tena@huawei.com>
Subject: Re: [BEHAVE] Port Management To Reduce Logging In Large-Scale NATs
X-BeenThere: behave@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: mailing list of BEHAVE IETF WG <behave.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/behave>
List-Post: <mailto:behave@ietf.org>
List-Help: <mailto:behave-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Sep 2010 05:21:48 -0000

Dear Olivier, all,

Compression is needed whatever the scheme adopted for the port assignment, especially to reduce the amount of exchanges between the mediation platform (responsible for collecting legal storage data from several location in the network) and the CGN device.

BTW, I agree with Joel's position: The way logs are built does not need to be standardised and this is implementation-specific. 

The interest I see in draft-tsou is it documents a way for optimisation (which is already supported by various vendors) and encourages the servers to store the source port information. This second point can be encouraged further if (as already suggested by Dan Wing) it has shown that the integration of the source port number is an easy task to handle by servers and this modification has no (or minor) impact on existing tools used to manipulate logs stored by the servers.

Cheers,
Med
 

-----Message d'origine-----
De : Olivier Vautrin [mailto:ovautrin@juniper.net] 
Envoyé : dimanche 5 septembre 2010 08:41
À : BOUCADAIR Mohamed NCPI/NAD/TIP; Lars Eggert
Cc : behave@ietf.org; Tina TSOU
Objet : RE: [BEHAVE] Port Management To Reduce Logging In Large-Scale NATs

Hello Med,

Does that mean you don't expect providers to Compress/Optimize the logs information sent per CGN device at all? 

In my understanding, this proposition will have an effect on the storage of log files only if the logs are kept *as is*. This is because the ports are randomly choosen in draft-tsou-behave-natx4-log-reduction-01, range are not created with contiguous ports so the amount of information sent by the CGN is not decreasing only the syslog message has changed.

Regards,
Olivier.

> > (3) As an aside effect, when port ranges are used the size of the log
> file is optimised (FWIW, see http://tools.ietf.org/html/draft-
> boucadair-port-range-02#section-15.2 for a simplified exercise). Of
> course this optimisation depends on length of the port range.
> 
> I understand that ranges shorten the log file. The point I was trying
> to make is that even on very large CGNs (large enough so that they'd
> need an insane amount of bandwidth to forward all the traffic they're
> seeing), the log sizes are not unmanageable. Sure, they can always be
> reduced, but that's an optional optimization.
> 
> Med: When the factor is 1000, then optimisation can not be seen as a
> luxe.

*********************************
This message and any attachments (the "message") are confidential and intended solely for the addressees. 
Any unauthorised use or dissemination is prohibited.
Messages are susceptible to alteration. 
France Telecom Group shall not be liable for the message if altered, changed or falsified.
If you are not the intended addressee of this message, please cancel it immediately and inform the sender.
********************************