Re: [LUNI] Can ISP's detect NAT usage? Please just stop worring about this. It is a non issue.

From: Tom Yarrish (tom@yarrish.com)
Date: Fri Mar 30 2001 - 08:10:18 CST

  • Next message: Stephen Boulet: "Re: [LUNI] slow posts..."

    Well, technically, wouldn't the ISP be able to use a packet sniffer of
    some sort? That will show that the IP packet has been modified for the
    NAT'd addres no? Mind you depending on the sniffer, you would be going
    through a lot of crap, but it would still be possible.

    Tom

    -- 
    #!/usr/bin/perl -w # 526-byte qrpff, Keith Winstein and Marc Horowitz
    <sipb-iap-dvd@mit.edu> # MPEG 2 PS VOB file on stdin -> descrambled output
    on stdout # arguments: title key bytes in least to most-significant order
    $_='while(read+STDIN,$_,2048){$a=29;$c=142;if((@a=unx"C*",$_)[20]&48){$h=5;
    $_=unxb24,join"",@b=map{xB8,unxb8,chr($_^$a[--$h+84])}@ARGV;s/...$/1$&/;$d=
    unxV,xb25,$_;$b=73;$e=256|(ord$b[4])<<9|ord$b[3];$d=$d>>8^($f=($t=255)&($d
    >>12^$d>>4^$d^$d/8))<<17,$e=$e>>8^($t&($g=($q=$e>>14&7^$e)^$q*8^$q<<6))<<9
    ,$_=(map{$_%16or$t^=$c^=($m=(11,10,116,100,11,122,20,100)[$_/16%8])&110;$t
    ^=(72,@z=(64,72,$a^=12*($_%16-2?0:$m&17)),$b^=$_%64?12:0,@z)[$_%8]}(16..271))
    [$_]^(($h>>=8)+=$f+(~$g&$t))for@a[128..$#a]}print+x"C*",@a}';s/x/pack+/g;eval
    

    On Fri, 30 Mar 2001, Joel Kulesa wrote:

    > > What I really wanted to know: Is there any way for an ISP to detect NAT > > usage? The question sprung from a discussion with a friend ... he told > > me that various DSL ISP's disallowed NAT and were able to detect it. > > But he didn't know how they did it. > > There really is no DIRECT way to do it to my knowledge. NAT is a rewriteing > of a packet so that all outgoing packets are origionating from the > NAT box. The box keeps tables of connections and ports so it knows > how to redirect(and rewrite) incoming packets (aka replies from > "out there") back to the true source machine. The only evidence per se, > is in the NAT table on *your* router/NAT box. > > However, one could start to be suspicious of the traffic > coming from a NAT device as being "one computer" and setup some > thresholds that would cause a trigger. Seems like alot of work to > me. > > jk > -- > Joel Kulesa http://pobox.com/~kulesa/ kulesa@takemeoutpobox.com > -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- > Aim Low, Reach Your Goals, Avoid Disappointment. > > -=- > Linux Users Of Northern Illinois: General Discussion Mailing list. > For unsubscription, archives, and announcements only see http://luni.org > >

    -=- Linux Users Of Northern Illinois: General Discussion Mailing list. For unsubscription, archives, and announcements only see http://luni.org



    This archive was generated by hypermail 2b29 : Fri Mar 30 2001 - 09:14:17 CST

  •