NAT Static Source Tracing Algorithm

Generally, NAT selects public IP addresses in an address pool and assigns the public IP addresses to private network packets. If user packets need to be traced, the NAT device needs to send source tracing logs. The NetEngine 8000 F also supports the static NAT source tracing algorithm so that user source tracing is performed without source tracing logs sent.

Fundamentals

The static source tracing algorithm provides a formula with the input of a private IP address range, a public IP address range, a port range size, and a port range and the output of the mapping between each private IP address and a pair of a public IP address range and a port range. The algorithm used in NAT translation defines mappings between private IP addresses and a pair of a public IP address range and a port range. A network element can use the algorithm to perform NAT user tracing if the network element obtains the NAT source tracing parameters the same as those configured on a NAT device, without receiving source tracing logs sent by the NAT device.

Benefits

Different from NAT444 source tracing, the static source tracing algorithm used on a NAT device does not send source tracing logs to the log server. Source tracing is complete by searching for the mapping between private and public network information stored in the static source tracing algorithm file on a source tracing device (for example, a log server).

With the static source tracing algorithm, a small number of public IP addresses can be allocated to a large number of private IP addresses, and the mapping between private and public IP addresses as well as the port range remains unchanged, which facilitates maintenance.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >