SDP RTP NAT Christian Huitema What NAT do

  • Slides: 4
Download presentation
SDP & RTP & NAT Christian Huitema

SDP & RTP & NAT Christian Huitema

What NAT do • Map ports “Real” Internet • Firewall variants S 64. 5.

What NAT do • Map ports “Real” Internet • Firewall variants S 64. 5. 6. 7: 8901 NAT Natted area Node 10. 0. 0. 1: 2345 – TCP connection – UDP stream (activity) – One port, any peer – One port, any “authorized” peer – One port per peer • Two problems – Make NAT “UDP friendly”, – Use random port numbers for RTP, RTCP

Recommendation for NAT: draft-huitema-natreq 4 udp-00. txt • Two mapping variants – Same port

Recommendation for NAT: draft-huitema-natreq 4 udp-00. txt • Two mapping variants – Same port / Different port “Real” Internet S • Two firewall variants T 64. 5. 6. 7: ? ? 64. 5. 6. 7: 8901 NAT Natted area • Problem – Different ports make “conferencing” very hard – Firewall makes “call transfer” and “signalling” hard – Not secure anyway… • Recommendation – Use same mapping, – Don’t “firewall” the user. Node 10. 0. 0. 1: 2345 – Accept / Require “activity” • Can we publish it, please?

Document mapping in SDP: draft-huitema-natreq 4 udp-00. txt • NAT map RTP, RTCP –

Document mapping in SDP: draft-huitema-natreq 4 udp-00. txt • NAT map RTP, RTCP – Oddity ? – Sequencing ? “Real” Internet E T • Mapping can be learned – Use “echo server” • Proposal: document in SDP 64. 5. 6. 7: 8901 64. 5. 6. 7: 7654 – Allow RTP > odd port – “a=rtcp=7654” NAT • AVT comment – If deviate oddity, document two ports. Natted area • Decision 10. 0. 0. 1: 3456 10. 0. 0. 1: 3457 Node – Last call ?