Re: [Ntp] NAT devices not translating privileged ports

Fernando Gont <fernando.gont@edgeuno.com> Mon, 07 June 2021 16:56 UTC

Return-Path: <fernando.gont@edgeuno.com>
X-Original-To: ntp@ietfa.amsl.com
Delivered-To: ntp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C55C63A3E4C for <ntp@ietfa.amsl.com>; Mon, 7 Jun 2021 09:56:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=edgeuno.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id emyk1sjxu-00 for <ntp@ietfa.amsl.com>; Mon, 7 Jun 2021 09:55:56 -0700 (PDT)
Received: from NAM10-BN7-obe.outbound.protection.outlook.com (mail-bn7nam10on2106.outbound.protection.outlook.com [40.107.92.106]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1B9DE3A3E4B for <ntp@ietf.org>; Mon, 7 Jun 2021 09:55:55 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=IHJox58frjZYK4/xVgTm4+IrqEaINM7OjmlmC3ExWSsYysuhooHcEFQ1DIkdQNAQ+pVUYk4/MGLUfYmObk25hEYrzzEhYUQxSBFbVlue8834Zfumb28ib5hKmGgOPpaGlo5Md1ZGYOorIcAUez0yVkgBunYrWKinEuADokh9nkWMenEytRsA68Br2liaKbipMlNIUSxiyOsxVYix0pG6leqeN89dXaKEjflJq2ZVw8DDNuzgRGwauiG6e+yLsisMVPeauKXmeiW/utwY+249n0H1k/2dz9gcj4PcdBdOsOT8Z31sxjZIPDcxkqT2uh2JA4ly6ay48fczzF4kSnGlTQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=RdjaJCRLRknNh7d7ysAX+2HzgikSKPUkdK32gi6fpiI=; b=Azwc5qgRwzQaIWbAAe9ziUMwBtiMAIlCTXlwtCTIuvcJx5YC+/EE9ecHRfR22jRoafmCW/Rde//CrNJuqOhnGvr86AeqtxJbzLDVuD2Q+vZwfGbQVAqWTQddT+rnTT2lM1ROdtPNBvjR+E23liFwn/FhVGNSjlbBtNbXYk2vKkniYLMlI/A2+DKbTUS1yOn/4yMkwGAq6mvkRlmIMJIipzf5SKjTJ13AcgMFBe0qKqcULTwWwqv6oJbuPm1P9/xXyM34R4Ck54kuP4TLRIvQ93UHqhk+ygVFfOVb17qWpwi0g5BkONVgKjI36CqUUATUE+A2OCcpGpSm2p+52WC1LQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=edgeuno.com; dmarc=pass action=none header.from=edgeuno.com; dkim=pass header.d=edgeuno.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=edgeuno.onmicrosoft.com; s=selector1-edgeuno-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=RdjaJCRLRknNh7d7ysAX+2HzgikSKPUkdK32gi6fpiI=; b=aqIaPKY3Cr8LlfomwaftwEyzlzoYH+hmG7qPW5bNPmEsbWcpZ17Wa7YEVP7++01nGYgVXeHKkaiqqrWfvZtEh8qxkfzKHXfRS+heFYF1UbA9os/0PWiqTQg2y+4mt8zc/2KLKawi1DQevi+i/5fuHSAiBUWG3uCLFM1Cd3TXT08=
Received: from SJ0PR05MB7514.namprd05.prod.outlook.com (2603:10b6:a03:2eb::6) by BYAPR05MB6358.namprd05.prod.outlook.com (2603:10b6:a03:e4::32) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4219.9; Mon, 7 Jun 2021 16:55:50 +0000
Received: from SJ0PR05MB7514.namprd05.prod.outlook.com ([fe80::59c9:fcf7:eeea:1148]) by SJ0PR05MB7514.namprd05.prod.outlook.com ([fe80::59c9:fcf7:eeea:1148%8]) with mapi id 15.20.4219.019; Mon, 7 Jun 2021 16:55:50 +0000
From: Fernando Gont <fernando.gont@edgeuno.com>
To: "halmurray+ietf@sonic.net" <halmurray+ietf@sonic.net>
CC: "ntp@ietf.org" <ntp@ietf.org>
Thread-Topic: [Ntp] NAT devices not translating privileged ports
Thread-Index: AQHXWRilpgEKLLHYY0CpbgJKOZ9vPqsIybuA
Date: Mon, 07 Jun 2021 16:55:49 +0000
Message-ID: <8f419eaceb273c10e56cffcadcc2241321090854.camel@edgeuno.com>
References: <20210604080716.167CD40605C@ip-64-139-1-69.sjc.megapath.net>
In-Reply-To: <20210604080716.167CD40605C@ip-64-139-1-69.sjc.megapath.net>
Accept-Language: es-AR, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Evolution 3.36.4-0ubuntu1
authentication-results: sonic.net; dkim=none (message not signed) header.d=none;sonic.net; dmarc=none action=none header.from=edgeuno.com;
x-originating-ip: [186.19.8.47]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 9776a83e-f3a1-440a-467d-08d929d51adf
x-ms-traffictypediagnostic: BYAPR05MB6358:
x-microsoft-antispam-prvs: <BYAPR05MB635878C46BDD6D17DF37369BE5389@BYAPR05MB6358.namprd05.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 5o0fY67Frl8uV4AyaskPWyx3rI9RVXolfKb7SjATy3uxha3wVi3OKyljaDiFKsV3lb+BKQia896LQEovJ72dJx92JugHX7o7ooaMVn3SpWk0OS9Srb1ka0yy05gtE4tvX3/XTuRwBX1xu7iqddabbFokw073FmxuV2kM/kqH0g0sAWCWwuX7N5DXRtun/jVGyGFBEoVXuFA69W047W30pCEzWjjVHL9iOQSRPRNfdVE0c8xNNbcgutXh7Pmr6gTuX/juIRN16uDc+pM1CskQlDDG0bdl91Ye3DHF/vHCJcyhi7oeL9U9zZnAyLgseCIcKclp/CE1hbR9LDbvTvB/I94RZXXTgXnACeLxXT6bQvDG53x08lpX3b8SfJtpB5zNp7hYY+bLyEu+9XRP9RKgCl0vSMzhxv9i95Q4thrnb4/1ijzvTatmDlMutZeSg4PAdd5qdbmOYyJlnBsxrwa3FEJB5I9o4G5C8aekTgh0du2ktA0Wj4/BGYZW5VQd65Y+bK4UEvIzVEp4pEGzcaciASHCMatjsbhKtsRAgcixUoddYb2M1OuSYEj6PbU1gpqeEhIO7ZP9/loGC3VUn9J1t9ZrcNGu2n1vScIcvXt/+7s=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SJ0PR05MB7514.namprd05.prod.outlook.com; PTR:; CAT:NONE; SFS:(376002)(366004)(346002)(39830400003)(396003)(136003)(36756003)(8936002)(478600001)(26005)(8676002)(2616005)(6506007)(2906002)(122000001)(71200400001)(4744005)(38100700002)(76116006)(91956017)(83380400001)(66446008)(64756008)(66946007)(66476007)(66556008)(5660300002)(6512007)(86362001)(316002)(186003)(6486002)(4326008)(44832011); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: eBvzUI/zUcRfCYByzrbCUl3pLP5XvxoTJhuHjPlsuKmv50Nwy0G4KQ25OJySqj3Cvrk5jW2ppEtGVliYa9RntBj2ihMU4G/YA3DNRNnWZaGo7wfKGnjxUqkDWYNcXj/kBHsNyYzP/KkUdLIVe4FvSj/ApKcTWHdLy5ZBAGlsoXTIWMNH9QMRBJrSKiJBGdG+U27LLRrOaslOej5PhLky3+qdyc7D1oVo5yH7pNTpOsssVdX7u6/c//G4uxXrYw9WCc6TF23XZFT0TvDM7rwQk/q7/O+jFGnfoac80gt3O1YDeHMOq9cUMxQLOMD5lANMRUw9slkUhpWoe0g+b3QjLp5688n3+K0qAREhg+P6vhYKZoNhDxWTre3rYygSfZeY0dri6+S/MposOZypJMfC0iep7W4S8XH1zT2/FpUaD6elKOEJdfJ5HlCsY8eFXuwdUt3DsrF6IIZ7PRQdGK+gaWEp8G0+McfgKddF3PFuagfjdLNcTTuSmdO4RRfwDzja1MwrZSnmFRb8gXzZTX9uTKUCrfYvBR9/p7xvGZom4yE0ULTuXYR8o8yTM+YcsMqDf9JLxmGw7LpQw5k2Tn0lQ1xXhAPNdll9vZt04ZJrV8boLN/O/+dlKr14ZqBo5Ajl6qtX6ZhrubGYL0VT4a6+MlVZgRLR9s+eC6fTRVPA/pHDVp7GC6g3qpYZCNRwadO4nERTSFFvjh8iD24UpXUHdRuvNGy4kbpFV1MV5crTELvw/DRxZ4fWsj414NNCKonzXrKrzMk1JPISCc5EKFtyKs3fgKSeVC2FKDrju9RVgmpCiGI+cxzCnuoxTSKe4iIsZr9ZGd3BYb//VXqRQo2d8hSeL6+7k9vraK+CGbLZm1YTHf5Pfy6HMzgbPWKoKulmWhUpfqieNpxL6c3cPlQqzSH7p+HLAes1dKd6jRJAm9QgInrhogy+o9Srbl1hnixHbtdUtFFXWrsS1rMZAXvs8RyhmX8BFpptG8GSX/JedNhtj/+K7fEBWNrCJjjIy6aOaS2rwcd2IR4dWzYaLCyeVHcwVZ67DPn9GbSdEYIxeVqvu9MNdlbas3PpAptjdBRCIZLUcRLqe/+eeUM6Aa0Tw7DY5aXXdN8SCYxGX2iHjLIA0W1gk//s0d/KBV70gI5PONS2OlG34MVWjr+p0yq4/Ct+0fOYX1vBb2AOnJouLlYS1S0yWx5uARQd925cixFRegMO0JEqv5WFEmW8ACB/wKYLM7QLuBoNXPnVxCRy0KJusntoz0yUXec3/nlOowq1TlbvQEhODinUyTCxdtXGzTJaW/ZdIV05j1FZ/qHgw64kjY+ln5oQX3YOQD+eA8QA
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <D211DE64CC17F04E8C9C4B083FD225B3@namprd05.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: edgeuno.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR05MB7514.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 9776a83e-f3a1-440a-467d-08d929d51adf
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Jun 2021 16:55:50.3874 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 20879dba-fabf-45da-8300-60b8ce560217
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Rl2FyM26AaHlgOias+nvgDaeEfJCNmJ6b5N3G/6bkTD2S/vqzF03Hy4luKETSAXnm9Bzh8zB4lCj74NNNVY+1nVJj/WlydyXw9zrZiDacJE=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR05MB6358
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/3qARzD1K1IwPjQc8U-_xne-N2c0>
Subject: Re: [Ntp] NAT devices not translating privileged ports
X-BeenThere: ntp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <ntp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ntp>, <mailto:ntp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp/>
List-Post: <mailto:ntp@ietf.org>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ntp>, <mailto:ntp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jun 2021 16:56:02 -0000

Hello, Hal,

On Fri, 2021-06-04 at 01:07 -0700, Hal Murray wrote:
> fernando.gont@edgeuno.com said:
> > we were asked if we could provide a reference for the NAT devices
> > do not
> > translate the source port if the source port is a privileged port
> > (<1024).
> > Any clues/examples of this type of NATs?
> 
> Does that make sense?

FWIW, we're not discussing whether that makes sense, but rather wether
there are devices that do that. :-)



>   What happens if 3 systems inside the NAT box all send 
> using the same privileged source port?  ntpd without port
> randomization would 
> do that.

Indeed, such behavior would break these deployments.

FWIW, this case was raised on this mailing-list -- hence I-m asknig for
references here...

Thanks!

Regards,
-- 
Fernando Gont
Director of Information Security
EdgeUno, Inc.
PGP Fingerprint: DFBD 63E3 B248 AE79 C598 AF23 EBAE DA03 0644 1531