Re: [pcp] A question: How can an internal client get the external IP and port of the inner NAT

🔓Dan Wing <dwing@cisco.com> Sat, 24 October 2015 15:57 UTC

Return-Path: <dwing@cisco.com>
X-Original-To: pcp@ietfa.amsl.com
Delivered-To: pcp@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA4EC1A1B84 for <pcp@ietfa.amsl.com>; Sat, 24 Oct 2015 08:57:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -12.629
X-Spam-Level:
X-Spam-Status: No, score=-12.629 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_FONT_FACE_BAD=0.981, HTML_MESSAGE=0.001, J_CHICKENPOX_35=0.6, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xCoGBQy1SESj for <pcp@ietfa.amsl.com>; Sat, 24 Oct 2015 08:57:16 -0700 (PDT)
Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6B9A11A1B76 for <pcp@ietf.org>; Sat, 24 Oct 2015 08:57:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=17689; q=dns/txt; s=iport; t=1445702236; x=1446911836; h=mime-version:subject:from:in-reply-to:date:cc:message-id: references:to; bh=rcbaKNs91y2IjGRCFCj74q+y//fRhy9nEq0IqfxAfqk=; b=ULsgcyBOwEM3J0i7HYz7REonNC+uz6N9xulhLby+2BM0mJQ3oD21K3P4 tczEVfmIvtB+14aLZCN1kaCy1lUwXnAVZyc1DAffLg1qZ3vgF0moTKNag qFUUg+AhmqBkzpSmF/sSJlnMDXT2NVwFFne/O93U4/Eay2+6HJYowhNh+ Y=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AFAgDXqStW/51dJa1dgmlNVG++OQENgVoXAQmFfAKBJjgUAQEBAQEBAYEKhDIBAQEDAQEBASAyGQsFCwkCBwoDAQIBJwMCAicfCQgGE4gbAwoIDZUrnTeNSRiESwEBAQEBAQEBAQEBAQEBAQEBAQEBARiGd4IQgm6EKgoHAQY6DAEEB4JpMYEUBYdChkuEVYNUjSKBWYQ/gwGPJoNwHwEBQoJEgV8eNIVPCReBKQEBAQ
X-IronPort-AV: E=Sophos;i="5.20,193,1444694400"; d="scan'208,217";a="200143801"
Received: from rcdn-core-6.cisco.com ([173.37.93.157]) by alln-iport-2.cisco.com with ESMTP; 24 Oct 2015 15:57:15 +0000
Received: from [10.24.216.150] ([10.24.216.150]) by rcdn-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id t9OFvEk1025095 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sat, 24 Oct 2015 15:57:14 GMT
Content-Type: multipart/alternative; boundary="Apple-Mail=_4D2319F3-68AD-4268-871E-46BDCEC760DA"
Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2104\))
From: =?utf-8?Q?=F0=9F=94=93Dan_Wing?= <dwing@cisco.com>
In-Reply-To: <BLU174-W5D1A00C9B465CC065759BC0250@phx.gbl>
Date: Sat, 24 Oct 2015 08:54:16 -0700
Message-Id: <877090F6-AA93-42DE-9010-345CA00E4641@cisco.com>
References: <70006713F8B28D4F88E17B98E1459AB5A3B8B47A@nkgeml501-mbs.china.huawei.com> <B3CC94E1-A9DF-45F2-99ED-5CA519920B3D@cisco.com> <BLU174-W5D1A00C9B465CC065759BC0250@phx.gbl>
To: ChenGuohai <chenguohai67@outlook.com>
X-Mailer: Apple Mail (2.2104)
Archived-At: <http://mailarchive.ietf.org/arch/msg/pcp/DCx_YHh09FZJWkBYWlf-Ih9qXb4>
Cc: "pcp@ietf.org" <pcp@ietf.org>
Subject: Re: [pcp] A question: How can an internal client get the external IP and port of the inner NAT
X-BeenThere: pcp@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: PCP wg discussion list <pcp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pcp>, <mailto:pcp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pcp/>
List-Post: <mailto:pcp@ietf.org>
List-Help: <mailto:pcp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pcp>, <mailto:pcp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 24 Oct 2015 15:57:19 -0000

On 23-Oct-2015 06:04 pm, ChenGuohai <chenguohai67@outlook.com>; wrote: 
> Hi Dan,
>  
> Many thanks for your explaination.
>  
> Inner NATs are mostly used in residents and external NATs are CGNs is the most common nested NAT case.
>  
> Using PCP means that the CPE(inner NAT) must embed a PCP server.  The PCP client should communicats with two PCP servers.

Right.


> Using STUN means a STUN server need to be deployed between inner NAT and external NAT. Shall this be common?

Not that I have seen.

-d


>  
> Manual configuration is very cost.
>  
>  
> BR
> G.Robert  Chen
>  
> Subject: Re: [pcp] A question: How can an internal client get the external IP and port of the inner NAT
> From: dwing@cisco.com
> Date: Fri, 23 Oct 2015 10:44:15 -0700
> CC: pcp@ietf.org; chenguohai67@outlook.com
> To: chenguohai@huawei.com
> 
> 
> On 22-Oct-2015 08:24 pm, Chenguohai <chenguohai@huawei.com <mailto:chenguohai@huawei.com>> wrote: 
>  
>  
> Hi all,
> I am new to PCP and reading RFC6887.I have a question about section 8.1. On the upper part of page 22 writing following,
> the PCP-controlled NAT creating pointless non-functional mappings.
>    When such an intervening non-PCP-aware inner NAT is detected,
>    mappings must first be created by some other means in the inner NAT,
>    before mappings can be usefully created in the outer PCP-controlled
>    NAT.  Having created mappings in the inner NAT by some other means,
>    the PCP client should then use the inner NAT’s external address as
>    the client IP address, to signal to the outer PCP-controlled NAT that
>    the client is aware of the inner NAT, and has taken steps to create
>    mappings in it by some other means, so that mappings created in the
>    outer NAT will not be a pointless waste of resources.
>  
> My question is that how an interal client could get the external IP and port of the inner NAT.
> 
> PCP, UPnP IGD, STUN, manual configuration.
> 
> Should there be server between the inner NAT and the external one? How could it be assured that the inner NAT does not change external port?
> 
> Hopefully whatever mechanism the client used (PCP, UPnP IGD, STUN, manual configuration) would tell the client of such a change.
> 
> -d
> 
> 
> 
>  
> BR
> G.Robert  Chen
> -------------------------------------------------------------------------------------------------------------------------------------
> G.Robert  Chen (Chen Guohai  陈国海). Network Research Department, Huawei Technologies Co., Ltd. Telephone: 0086-25-56624606;   http://www.huawei.com <http://www.huawei.com/>
> -------------------------------------------------------------------------------------------------------------------------------------
> This e-mail and its attachments contain confidential information from HUAWEI, which is intended only for the person or entity whose address is listed above. Any use of the  information contained herein in any way (including, but not limited to, total or partial disclosure, reproduction, or dissemination) by persons other than the intended recipient(s) is prohibited. If you receive this e-mail in error, please notify the sender by phone or email immediately and delete it!
> ----------------------------------------------------------------------------------------------------------------------------------------
>  
>  
>  
> _______________________________________________
> pcp mailing list
> pcp@ietf.org <mailto:pcp@ietf.org>
> https://www.ietf.org/mailman/listinfo/pcp
> 
>