Re: Logging the source port?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fri, Nov 13, 2009 at 02:59:23PM +0900,
 Joel Jaeggli <joelja@xxxxxxxxx> wrote 
 a message of 25 lines which said:

> common log format doesn't capture that information...

No, but it seems to be in the good old "CGI" variables, as
REMOTE_PORT. If you have a Web application, not just static Web pages,
and you log yourself, you probably have this information.
 
> that said, of the A-P or PAT box which isn't under your control in
> all likelyhood anyway doesn't log the association of internal
> devices to external ports then knowing the source port may not tell
> you that much about which client you're talking to...

Alain was referring to Carrier-Grade NAT, where an IP address is
shared between people of different households. When you have an IP
address shared only inside the family, it is usually not important to
identify a specific machine. But when you want to prosecute someone
based on the IP address of the request, it is important to
differentiate neighbours :-)

I assume that the NAT routers used by Internet access providers, for
their subscribers, will log the mapping user<->(address,port)
somewhere. (This is one of the points described in the draft.)

_______________________________________________
Ietf mailing list
Ietf@xxxxxxxx
https://www.ietf.org/mailman/listinfo/ietf

[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Fedora Users]