Educause Security Discussion mailing list archives
Re: Large edu's doing NAT campus wide?
From: Kenneth Arnold <bkarnold () CBU EDU>
Date: Sun, 29 Apr 2007 14:32:00 -0500
We aren't a large university but we have been using NAT for many years now. The main reason that we switched was because our ISP was changing its ISP and all of our IP addresses would have to change as a result. Since then we have changed ISPs at least one more time. Using NAT makes us independent of the IP addresses of our ISP so we can easily change ISPs in order to get a better deal. We don't own our IP addresses. Firewall syslogs can keep track of which internal IP address was using a given external IP address at any given time so that problems reported to us can be traced back to the device causing them. Brother Kenneth Arnold Christian Brothers University Chris Allison wrote:
All, I would be interested in hearing other peoples ideas concerning using a campus wide NAT to provide additional protection. At MU we are looking at adding NAT. The idea would be that the internal address space would not be reachable from outside unless you used VPN or talked to the security guys about setting up a static IP and associated NAT map. As you might imagine, a number of academic types don't like the idea. For the most part, they have not created a convincing argument against. My experience is they don't really come after you until after you pull the switch. With all the devices coming onto campus, one does not have to look far to see we will have addressing problems soon. In fact we are already having point issues and the occurrences are becoming more frequent. We don't yet have experience with campus wide NAT, so I would very much like to know about others and; Joe, Could you send me any responses you received? Thanks, Chris Allison, PMP Miami University
Current thread:
- Large edu's doing NAT campus wide? Joe St Sauver (Apr 28)
- <Possible follow-ups>
- Re: Large edu's doing NAT campus wide? Scott O. Bradner (Apr 28)
- Re: Large edu's doing NAT campus wide? Randy Marchany (Apr 28)
- Re: Large edu's doing NAT campus wide? Randall C Grimshaw (Apr 29)
- Re: Large edu's doing NAT campus wide? Jeff Murphy (Apr 29)
- Re: Large edu's doing NAT campus wide? Joe St Sauver (Apr 29)
- Re: Large edu's doing NAT campus wide? Chris Allison (Apr 29)
- Re: Large edu's doing NAT campus wide? Kenneth Arnold (Apr 29)
- Re: Large edu's doing NAT campus wide? Russell Fulton (Apr 29)
- Re: Large edu's doing NAT campus wide? Cal Frye (Apr 29)
- Re: Large edu's doing NAT campus wide? Jeff Kell (Apr 29)
- Large edu's doing NAT campus wide? Marcos Vieyra (Apr 30)
- Re: Large edu's doing NAT campus wide? Clifford Collins (Apr 30)
- Re: Large edu's doing NAT campus wide? Justin Azoff (Apr 30)
- Re: Large edu's doing NAT campus wide? Roger Safian (Apr 30)
- Re: Large edu's doing NAT campus wide? Brian Paige (Apr 30)
- Re: Large edu's doing NAT campus wide? John Ladwig (Apr 30)
- Re: Large edu's doing NAT campus wide? John Ladwig (Apr 30)
(Thread continues...)