[BEHAVE] Logging: address exhaustion and port exhaustion events

Tom Taylor <tom.taylor.stds@gmail.com> Sun, 29 September 2013 08:22 UTC

Return-Path: <tom.taylor.stds@gmail.com>
X-Original-To: behave@ietfa.amsl.com
Delivered-To: behave@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 644DF21F9609 for <behave@ietfa.amsl.com>; Sun, 29 Sep 2013 01:22:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.644
X-Spam-Level:
X-Spam-Status: No, score=-2.644 tagged_above=-999 required=5 tests=[AWL=-0.045, BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EQmVn-7ltMyI for <behave@ietfa.amsl.com>; Sun, 29 Sep 2013 01:22:45 -0700 (PDT)
Received: from mail-ie0-x22f.google.com (mail-ie0-x22f.google.com [IPv6:2607:f8b0:4001:c03::22f]) by ietfa.amsl.com (Postfix) with ESMTP id 5216021F9FA2 for <behave@ietf.org>; Sun, 29 Sep 2013 01:22:45 -0700 (PDT)
Received: by mail-ie0-f175.google.com with SMTP id e14so7385723iej.6 for <behave@ietf.org>; Sun, 29 Sep 2013 01:22:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:subject :content-type:content-transfer-encoding; bh=NNSq76xbV1nNVMbTk4MBJhGW5O3RvrKZMaC4kL0SdKk=; b=x5AL0tWmcSkKNDdvovanKf2vLMd2gkUsixGWIBORvk5DNd+h0OOXmLsTMpfsrMe2c+ VP8MJj3hXaa3zVsO8c4/8FRUcTH9cVif2t35DlNygiprg7NYNgj/TDMCnV5VPd2/oN0B N8Wlv5LzUAEnBp7jTagtKapb027aGbYpO+7YTd9J1e4rzVecvDIfkZhsHdqBUbSUe9nw ZwI6S+wDuTPPdoPuCqgKWCpef2SY5b3Z707KBwaQCNjX/UeIByo/SI27Rr0DwL2dzt5q p4TtXJ0OSUx/paHaiQ12kP6ItislGTcOfTDI5fnSQjhpVbbtlDNddEm6ovIiRiOeWhLI Hdag==
X-Received: by 10.42.63.194 with SMTP id d2mr12145095ici.10.1380442964315; Sun, 29 Sep 2013 01:22:44 -0700 (PDT)
Received: from [192.168.1.65] (dsl-173-206-79-23.tor.primus.ca. [173.206.79.23]) by mx.google.com with ESMTPSA id k6sm9377268igx.8.1969.12.31.16.00.00 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Sun, 29 Sep 2013 01:22:43 -0700 (PDT)
Message-ID: <5247E351.1070108@gmail.com>
Date: Sun, 29 Sep 2013 04:22:41 -0400
From: Tom Taylor <tom.taylor.stds@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:17.0) Gecko/20130801 Thunderbird/17.0.8
MIME-Version: 1.0
To: "behave@ietf.org" <behave@ietf.org>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Subject: [BEHAVE] Logging: address exhaustion and port exhaustion events
X-BeenThere: behave@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: mailing list of BEHAVE IETF WG <behave.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/behave>, <mailto:behave-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/behave>
List-Post: <mailto:behave@ietf.org>
List-Help: <mailto:behave-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 29 Sep 2013 08:22:47 -0000

In the -04 pass for the SYSLOG logging document, I added the following 
text in the section describing the address pool threshold events:

<begin>

The high-water-mark threshold event provides a warning that the
address-port combinations offered by the pool are nearing exhaustion.
Upon exhaustion, packets may be dropped because no address has enough
free port values left to be allocated to an address mapping ("address
exhaustion"). This applies to the case of "paired" pooling behaviour
[RFC4787], where typically an address will not be
allocated unless it has a sufficient number of free ports.
Alternatively, packets will be dropped simply because no address in the
pool has a free port number for the required protocol ("port
exhaustion").

Packets dropped due to address exhaustion are included in the amounts
provided by the following NAT MIB counters:
   o globally, natResourceErrors in the natCounters table;

   o per protocol, natProtocolResourceErrors in natProtocolTable;

   o per subscriber, natSubscriberResourceErrors in
     natSubscribersTable.>

Packets dropped due to port exhaustion are counted in the following
NAT MIB counters:
   o globally, natOutOfPortErrors in the natCounters table;
   o per protocol, natProtocolOutOfPortErrors in natProtocolTable;
   o per subscriber, natSubscriberOutOfPortErrors in
     natSubscribersTable.

<end>

First question: do people agree with the proposed definitions of address 
exhaustion and port exhaustion? If so, we have operational definitions a 
NAT can work with in generating both counts and logs.

Second question: our current OAM-related events are all based on 
administratively-set limits and thresholds. Should the address 
exhaustion and port exhaustion events also be logged?

Tom Taylor