Re: [Ntp] NAT devices not translating privileged ports

Fernando Gont <fernando.gont@edgeuno.com> Mon, 07 June 2021 16:56 UTC

Return-Path: <fernando.gont@edgeuno.com>
X-Original-To: ntp@ietfa.amsl.com
Delivered-To: ntp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C55C63A3E4C for <ntp@ietfa.amsl.com>; Mon, 7 Jun 2021 09:56:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=edgeuno.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id emyk1sjxu-00 for <ntp@ietfa.amsl.com>; Mon, 7 Jun 2021 09:55:56 -0700 (PDT)
Received: from NAM10-BN7-obe.outbound.protection.outlook.com (mail-bn7nam10on2106.outbound.protection.outlook.com [40.107.92.106]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1B9DE3A3E4B for <ntp@ietf.org>; Mon, 7 Jun 2021 09:55:55 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=IHJox58frjZYK4/xVgTm4+IrqEaINM7OjmlmC3ExWSsYysuhooHcEFQ1DIkdQNAQ+pVUYk4/MGLUfYmObk25hEYrzzEhYUQxSBFbVlue8834Zfumb28ib5hKmGgOPpaGlo5Md1ZGYOorIcAUez0yVkgBunYrWKinEuADokh9nkWMenEytRsA68Br2liaKbipMlNIUSxiyOsxVYix0pG6leqeN89dXaKEjflJq2ZVw8DDNuzgRGwauiG6e+yLsisMVPeauKXmeiW/utwY+249n0H1k/2dz9gcj4PcdBdOsOT8Z31sxjZIPDcxkqT2uh2JA4ly6ay48fczzF4kSnGlTQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=RdjaJCRLRknNh7d7ysAX+2HzgikSKPUkdK32gi6fpiI=; b=Azwc5qgRwzQaIWbAAe9ziUMwBtiMAIlCTXlwtCTIuvcJx5YC+/EE9ecHRfR22jRoafmCW/Rde//CrNJuqOhnGvr86AeqtxJbzLDVuD2Q+vZwfGbQVAqWTQddT+rnTT2lM1ROdtPNBvjR+E23liFwn/FhVGNSjlbBtNbXYk2vKkniYLMlI/A2+DKbTUS1yOn/4yMkwGAq6mvkRlmIMJIipzf5SKjTJ13AcgMFBe0qKqcULTwWwqv6oJbuPm1P9/xXyM34R4Ck54kuP4TLRIvQ93UHqhk+ygVFfOVb17qWpwi0g5BkONVgKjI36CqUUATUE+A2OCcpGpSm2p+52WC1LQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=edgeuno.com; dmarc=pass action=none header.from=edgeuno.com; dkim=pass header.d=edgeuno.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=edgeuno.onmicrosoft.com; s=selector1-edgeuno-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=RdjaJCRLRknNh7d7ysAX+2HzgikSKPUkdK32gi6fpiI=; b=aqIaPKY3Cr8LlfomwaftwEyzlzoYH+hmG7qPW5bNPmEsbWcpZ17Wa7YEVP7++01nGYgVXeHKkaiqqrWfvZtEh8qxkfzKHXfRS+heFYF1UbA9os/0PWiqTQg2y+4mt8zc/2KLKawi1DQevi+i/5fuHSAiBUWG3uCLFM1Cd3TXT08=
Received: from SJ0PR05MB7514.namprd05.prod.outlook.com (2603:10b6:a03:2eb::6) by BYAPR05MB6358.namprd05.prod.outlook.com (2603:10b6:a03:e4::32) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4219.9; Mon, 7 Jun 2021 16:55:50 +0000
Received: from SJ0PR05MB7514.namprd05.prod.outlook.com ([fe80::59c9:fcf7:eeea:1148]) by SJ0PR05MB7514.namprd05.prod.outlook.com ([fe80::59c9:fcf7:eeea:1148%8]) with mapi id 15.20.4219.019; Mon, 7 Jun 2021 16:55:50 +0000
From: Fernando Gont <fernando.gont@edgeuno.com>
To: "halmurray+ietf@sonic.net" <halmurray+ietf@sonic.net>
CC: "ntp@ietf.org" <ntp@ietf.org>
Thread-Topic: [Ntp] NAT devices not translating privileged ports
Thread-Index: AQHXWRilpgEKLLHYY0CpbgJKOZ9vPqsIybuA
Date: Mon, 7 Jun 2021 16:55:49 +0000
Message-ID: <8f419eaceb273c10e56cffcadcc2241321090854.camel@edgeuno.com>
References: <20210604080716.167CD40605C@ip-64-139-1-69.sjc.megapath.net>
In-Reply-To: <20210604080716.167CD40605C@ip-64-139-1-69.sjc.megapath.net>
Accept-Language: es-AR, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Evolution 3.36.4-0ubuntu1
authentication-results: sonic.net; dkim=none (message not signed) header.d=none;sonic.net; dmarc=none action=none header.from=edgeuno.com;
x-originating-ip: [186.19.8.47]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 9776a83e-f3a1-440a-467d-08d929d51adf
x-ms-traffictypediagnostic: BYAPR05MB6358:
x-microsoft-antispam-prvs: <BYAPR05MB635878C46BDD6D17DF37369BE5389@BYAPR05MB6358.namprd05.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 5o0fY67Frl8uV4AyaskPWyx3rI9RVXolfKb7SjATy3uxha3wVi3OKyljaDiFKsV3lb+BKQia896LQEovJ72dJx92JugHX7o7ooaMVn3SpWk0OS9Srb1ka0yy05gtE4tvX3/XTuRwBX1xu7iqddabbFokw073FmxuV2kM/kqH0g0sAWCWwuX7N5DXRtun/jVGyGFBEoVXuFA69W047W30pCEzWjjVHL9iOQSRPRNfdVE0c8xNNbcgutXh7Pmr6gTuX/juIRN16uDc+pM1CskQlDDG0bdl91Ye3DHF/vHCJcyhi7oeL9U9zZnAyLgseCIcKclp/CE1hbR9LDbvTvB/I94RZXXTgXnACeLxXT6bQvDG53x08lpX3b8SfJtpB5zNp7hYY+bLyEu+9XRP9RKgCl0vSMzhxv9i95Q4thrnb4/1ijzvTatmDlMutZeSg4PAdd5qdbmOYyJlnBsxrwa3FEJB5I9o4G5C8aekTgh0du2ktA0Wj4/BGYZW5VQd65Y+bK4UEvIzVEp4pEGzcaciASHCMatjsbhKtsRAgcixUoddYb2M1OuSYEj6PbU1gpqeEhIO7ZP9/loGC3VUn9J1t9ZrcNGu2n1vScIcvXt/+7s=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SJ0PR05MB7514.namprd05.prod.outlook.com; PTR:; CAT:NONE; SFS:(376002)(366004)(346002)(39830400003)(396003)(136003)(36756003)(8936002)(478600001)(26005)(8676002)(2616005)(6506007)(2906002)(122000001)(71200400001)(4744005)(38100700002)(76116006)(91956017)(83380400001)(66446008)(64756008)(66946007)(66476007)(66556008)(5660300002)(6512007)(86362001)(316002)(186003)(6486002)(4326008)(44832011); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: =?utf-8?B?ZUJ2elVJL3pVY1JmQ1lCeXpyYkNVbDNwTFA1WHZ4b1RKaHVIalBsc3VLbXY1?= =?utf-8?B?ME53eTBHNEtRMjVPSnlTcWozQ3ZyazVqVzJwcEV0R1ZsaVlhOVJudEJqMmlo?= =?utf-8?B?TVU0Ry9ZQTNETlJObldaYUdvN3dmS0duanhVcWtEV1lOY1hqL2tCSHNOeVl6?= =?utf-8?B?UC9La1VkTElWZTRGdlNqL0FwS2NUV0hkTHk1WkJBR2xzb1hUSVdNTkg5UU1S?= =?utf-8?B?QkpyU0tpSkJHZEcrVTI3TExSck9hc2xPZWo1UGhMa3kzK3FkeWM3RDFvVm81?= =?utf-8?B?eUg3cE5UcE9zc3NWZFg3dTYvYy8vRzR1eFhyWXc5V0NjNlRGMjNYWkZUMFR2?= =?utf-8?B?RE03cndRay9xNy9PK2pGR25mb2FjODBndDNPMVlEZUhNT3E5Y1VNeFFMT01E?= =?utf-8?B?NWxBTk1SVXc5c2xrVWhwV29lMGcrYjNRakxwNTY4OG4zK0swcUFSRWhnK1A2?= =?utf-8?B?dmhZS1pvTmhEeFdUcmUzcll5Z1NmWmVZMGRyaTYrUy9NcG9zT1p5cEpNZkMw?= =?utf-8?B?aWVwN1c0UzhYSDF6VDIvRnBVYUQ2ZWxLT0VKZGZKNUhsQ3NZOGVGWHV3ZFV0?= =?utf-8?B?M0RzckY2SUlaN1BSUWRHSytnYVdFcDhHMCtNY2ZnS2RkRjNQRnVhZ2ZqZExO?= =?utf-8?B?Y1RUdVNtZE80UlJmd0R6amExTXdyWlNubUZSYjhnWHpaVFg5dVRLVUNyZll2?= =?utf-8?B?QlI5L3A3eHZHWm9tNHlFMFVMVHVYWVI4bzh5VE0rWWNzTXFEZjlKTHhtR3c3?= =?utf-8?B?THBRdzVrMlRuMGxRMXhYaEFQTmRsbDl2WnQwNFpKclY4Ym9MTi9PLytkbEty?= =?utf-8?B?MTRacUJvNUFqbDZxdFg2WmhydWJHWUwwVlQ0YTYrTWxWWmdSTFI5cytlQzZm?= =?utf-8?B?VFJWUEEvcEhEVnA3R0M2ZzNxcFlaQ05Sd2FkTzRuRVJUU0ZGdmpoOGlEMjRV?= =?utf-8?B?cFhVSGRSdXZOR3k0a2JwRlYxTVY1Y3JURUx2dy9EUnhaNGZXc2o0MTROTkNL?= =?utf-8?B?b256WHJLcnpNazFKUElTQ2M1RUtGdHlLczNmZ0tTZVZDMkZLRHJqdTlSVmdt?= =?utf-8?B?cENpR0krY3h6Q251b3hUU0tlNGlJc1pyOVpHZDNCWWIvL1ZYcVJRbzJkOGhT?= =?utf-8?B?ZUw2KzdrOXZyYUsrQ0diTFptMVlUSGY1UGZ5NkhNemdiUFdLb0t1bG1XaFVw?= =?utf-8?B?ZnFpZU5weEw2YzNjUGxRcXpTSDdwK0hMQWVzMWRLZDZqUkpBbTlRZ0lucmhv?= =?utf-8?B?Z3krbzlTcmJsMWhuaXhIYnRkVXRGRlhXcnNTMXJNWkFYdnM4UnlobVg4QkZw?= =?utf-8?B?cHRHOEdTWC9KZWROaHRqLytLN2ZFQldOckNKampJeTZhT2FTMnJ3Y2QySVI0?= =?utf-8?B?ZFd6WWFMQ3llVkhjd1ZaNjdEUG45R2JTZEVZSXhlVnF2dTlNTmRsYmFzM1Bw?= =?utf-8?B?QXB0amRCUkNJWkxVY1JMcWUvK2VlVU02QWEwVHc3RFk1YVhYZE44U0NZeEdY?= =?utf-8?B?MmlIakxJQTBXMWdrLy9zMGQvS0JWNzBnSTVQT05TMk9sRzM0TVZXanIrcDB5?= =?utf-8?B?cTQvQ3QrMGZPWVgxdkJiMkFPbkpvdUxsWVMxUzB5V3g1dUFSUWQ5MjVjaXhG?= =?utf-8?B?UmVnTU8wSkVxdjVXRkVtVzhBQ0Ivd0tZTE03UUx1Qm9OWFBuVnhDUnkwS0p1?= =?utf-8?B?c250b3oweVVYZWMzL25sT293cTFUbGJ2UUVoT0RpblV5VEN4ZHRYR3pUSmFX?= =?utf-8?Q?/ZdIV05j1FZ/qHgw64kjY+ln5oQX3YOQD+eA8QA?=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <D211DE64CC17F04E8C9C4B083FD225B3@namprd05.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: edgeuno.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR05MB7514.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 9776a83e-f3a1-440a-467d-08d929d51adf
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Jun 2021 16:55:50.3874 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 20879dba-fabf-45da-8300-60b8ce560217
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Rl2FyM26AaHlgOias+nvgDaeEfJCNmJ6b5N3G/6bkTD2S/vqzF03Hy4luKETSAXnm9Bzh8zB4lCj74NNNVY+1nVJj/WlydyXw9zrZiDacJE=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR05MB6358
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/3qARzD1K1IwPjQc8U-_xne-N2c0>
Subject: Re: [Ntp] NAT devices not translating privileged ports
X-BeenThere: ntp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <ntp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ntp>, <mailto:ntp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp/>
List-Post: <mailto:ntp@ietf.org>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ntp>, <mailto:ntp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jun 2021 16:56:02 -0000

Hello, Hal,

On Fri, 2021-06-04 at 01:07 -0700, Hal Murray wrote:
> fernando.gont@edgeuno.com said:
> > we were asked if we could provide a reference for the NAT devices
> > do not
> > translate the source port if the source port is a privileged port
> > (<1024).
> > Any clues/examples of this type of NATs?
> 
> Does that make sense?

FWIW, we're not discussing whether that makes sense, but rather wether
there are devices that do that. :-)



>   What happens if 3 systems inside the NAT box all send 
> using the same privileged source port?  ntpd without port
> randomization would 
> do that.

Indeed, such behavior would break these deployments.

FWIW, this case was raised on this mailing-list -- hence I-m asknig for
references here...

Thanks!

Regards,
-- 
Fernando Gont
Director of Information Security
EdgeUno, Inc.
PGP Fingerprint: DFBD 63E3 B248 AE79 C598 AF23 EBAE DA03 0644 1531