Educause Security Discussion mailing list archives
Re: Large edu's doing NAT campus wide?
From: Joe St Sauver <joe () OREGON UOREGON EDU>
Date: Sun, 29 Apr 2007 08:24:47 -0700
Jeff mentioned: #I agree that the security aspects are debatable, but it's inline with #the conservative nature of security: permit only what's necessary. If a #device (LOM, KVM, printers, etc) don't need to be globally accessible, #yadda yadda. I probably should have mentioned the context for my query: I'm putting together a talk describing some of the ways in which higher ed system and network architectures might make attribution of traffic to a particular individual somewhat tricky w/o the timely and active participation of the local administrator(s). That is, there are many entities who seem to assume that IP address plus time stamp and time zone --> unique individual, and sometimes (when the end-to-end model holds up, and the stars otherwise align) that can be true. On the other hand, I think there may be a growing number of instances when an IP address plus a time stamp and time zone map to a few hundred (or thousand) individuals, and reducing the size of that set any further can only be done if you have access to log files, etc. Examples include: -- campus wide NATs using just one (or a small number of) shared public gateway address -- large shell account hosts (we could talk about identd I suppose) -- traffic from campus proxy servers (we could talk about things like HTTP_X_FORWARDED_FOR when it is used, I suppose) etc. Let me also take this opportunity to thanks all those who sent along examples of campus-wide NATs... Regards, Joe St Sauver (joe () oregon uoregon edu) http://www.uoregon.edu/~joe/
Current thread:
- Large edu's doing NAT campus wide? Joe St Sauver (Apr 28)
- <Possible follow-ups>
- Re: Large edu's doing NAT campus wide? Scott O. Bradner (Apr 28)
- Re: Large edu's doing NAT campus wide? Randy Marchany (Apr 28)
- Re: Large edu's doing NAT campus wide? Randall C Grimshaw (Apr 29)
- Re: Large edu's doing NAT campus wide? Jeff Murphy (Apr 29)
- Re: Large edu's doing NAT campus wide? Joe St Sauver (Apr 29)
- Re: Large edu's doing NAT campus wide? Chris Allison (Apr 29)
- Re: Large edu's doing NAT campus wide? Kenneth Arnold (Apr 29)
- Re: Large edu's doing NAT campus wide? Russell Fulton (Apr 29)
- Re: Large edu's doing NAT campus wide? Cal Frye (Apr 29)
- Re: Large edu's doing NAT campus wide? Jeff Kell (Apr 29)
- Large edu's doing NAT campus wide? Marcos Vieyra (Apr 30)
- Re: Large edu's doing NAT campus wide? Clifford Collins (Apr 30)
- Re: Large edu's doing NAT campus wide? Justin Azoff (Apr 30)
- Re: Large edu's doing NAT campus wide? Roger Safian (Apr 30)
- Re: Large edu's doing NAT campus wide? Brian Paige (Apr 30)
(Thread continues...)