IP Flow Information Export Information Elements for Logging NAT Events
RFC 8158, “IP Flow Information Export Information Elements for Logging NAT Events”, is a Proposed Standard document published in December 2017 by S. Sivakumar, R. Penno. The canonical text is published by the RFC Editor.
Abstract
Network operators require NAT devices to log events like creation and deletion of translations and information about the resources that the NAT device is managing. In many cases, the logs are essential to identify an attacker or a host that was used to launch malicious attacks and for various other purposes of accounting. Since there is no standard way of logging this information, different NAT devices use proprietary formats; hence, it is difficult to expect consistent behavior. This lack of standardization makes it difficult to write the Collector applications that would receive this data and process it to present useful information. This document describes the formats for logging NAT events.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8158 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8157 Huawei's GRE Tunnel Bonding Protocol
- RFC 8159 Keyed IPv6 Tunnel
- RFC 8156 DHCPv6 Failover Protocol
- RFC 8160 IUTF8 Terminal Mode in Secure Shell
- RFC 8155 Traversal Using Relays around NAT Server Auto Discovery
- RFC 8161 Benchmarking the Neighbor Discovery Protocol
- RFC 8154 Parallel NFS Small Computer System Interface Layout
- RFC 8162 Using Secure DNS to Associate Certificates with Domain Names for S/MIME