Large Scale NAT64
Architecture
Example: Traffic Flow of NAT64 and DNS64 Deployment
DNS64 Traffic Flow
www.example.com, which resides on an IPv4-only web server on the Internet, as follows:
-
IPv6 subscriber SUB-1 sends a DNS AAAA request for
www.example.comto its designated DNS server (2001:DB8:9999::99). -
DNS load balancing virtual server LBVS-DNS64-1 (2001:DB8:9999::99) on NetScaler appliance NS1 receives the AAAA request. LBVS-DNS64-1's load balancing algorithm selects DNS server DNS-1 and forwards the AAAA request to it.
-
DNS-1 returns an empty record or an error message, because there is no AAAA record available for
www.example.com. -
Because the DNS64 option is enabled on LBVS-DNS64-1 and the AAAA request from CL1 matches the condition specified in DNS64-Policy-1, NS1 sends a DNS A request to DNS-1 for the IPv4 address of
www.example.com. -
DNS-1 responds with the A record of 192.0.2.60 for
www.example.com. -
DNS64 module on NS1 synthesizes an AAAA record for
www.example.comby concatenating the DNS64 Prefix (2001:DB8:300::/96) associated with LBVS-DNS64-1, and IPv4 address (192.0.2.60) forwww.example.com= 2001:DB8:300::192.0.2.60 -
NS1 sends the synthesized AAAA record to IPv6 client CL1. NS1 also caches the A record into its memory. NS1 uses the cached A record to synthesize AAAA records for subsequent AAAA requests.
NAT64 Traffic Flow
-
IPv6 subscriber SUB-1 sends a request to 2001:DB8:5001:30
www.example.com. The IPv6 packet has:-
Source IP address = 2001:DB8:5001:30
-
Source port = 2552
-
Destination IP address = 2001:DB8:300::192.0.2.60
-
Destination port = 80
-
-
IPv6 subscriber SUB-1 sends a request to 2001:DB8:5001:30
www.example.com. The IPv6 packet has:-
Source IP address = 2001:DB8:5001:30
-
Source port = 2552
-
Destination IP address = 2001:DB8:300::192.0.2.60
-
Destination port = 80
-
-
When NS-1 receives the IPv6 packet, the large scale NAT64 module creates a translated IPv4 request packet with:
-
Source IP address = One of the IPv4 addresses available in the configured NAT pool (203.0.113.61)
-
Source port = One of ports available with the allocated NAT IPv4 address (3002)
-
Destination IP address = IPv4 address extracted from the IPv6 request’s destination address by stripping the NAT64 prefix (2001:DB8:300::/96) from the IPv6 address (192.0.2.60)
-
Destination port = IPv6 request’s destination port (80)
-
-
The large scale NAT64 module also creates mapping and session entries for this large scale NAT64 flow. The session and mapping entries include the following information:
-
Source IP address of the IPv6 packet = 2001:DB8:5001:30
-
Source port of the IPv6 packet = 2552
-
NAT IP address = 203.0.113.61
-
NAT port = 3002
-
NS-1 sends the resulting IPv4 packet to its destination on the Internet.
-
-
Upon receiving the request packet, the server for
www.example.comprocesses the packet and sends a response packet to NS-1. The IPv4 response packet has:-
Source IP address = 192.0.2.60
-
Source port = 80
-
Destination IP address = 203.0.113.61
-
Destination port = 3002
-
-
Upon receiving the IPv4 response packet, NS-1 examines the large scale NAT64 mapping and session entries and finds that the IPv4 response packet belongs to a large scale NAT64 session. The large scale NAT64 module creates a translated IPv6 response packet:
-
Source IP address = 2001:DB8:300::192.0.2.60
-
Source port = 80
-
Destination IP address = 2001:DB8:5001:30
-
Destination port = 2552
-
-
NS-1 sends the translated IPv6 response to client SUB-1.
Large Scale NAT64 features Supported on NetScaler appliances
-
ALGs. Support of application Layer Gateway (ALG) for SIP, RTSP, FTP, ICMP, and TFTP protocols.
-
Deterministic/Fixed NAT. Support for pre-allocation of blocks of ports to subscribers to minimize logging.
-
Mapping. Support of Endpoint-independent mapping (EIM), Address-dependent mapping (ADM), and Address-Port dependent mapping (APDM).
-
Filtering. Support of Endpoint-Independent Filtering (EIF), Address-Dependent Filtering (ADF), and Address-Port-Dependent Filtering (APDF).
-
Quotas. Configurable limits on number of ports, sessions per subscriber, and sessions per LSN group.
-
Static Mapping. Support for manually defining a large scale NAT64 mapping.
-
Hairpin Flow. Support for communication between subscribers or internal hosts using NAT IP addresses.
-
464XLAT connections. Support for communication between IPv4-only applications on IPv6 subscriber hosts and IPv4 hosts on the Internet through IPv6 network.
-
Variable length NAT64 and DNS64 prefixes. The NetScaler appliance supports defining NAT64 and DNS64 prefixes of lengths of 32, 40, 48, 56, 64, and 96.
-
Multiple NAT64 and DNS64 prefix. The NetScaler appliance supports multiple NAT64 and DNS64 prefixes.
-
LSN Clients. Support for specifying or identifying subscribers for large scale NAT64 by using IPv6 prefixes and extended ACL6 rules.
-
Logging. Support for logging NAT64 sessions for law enforcement. In addition, the following are also supported for logging.
-
Reliable SYSLOG. Support for sending SYSLOG messages over TCP to external log servers for a more reliable transport mechanism.
-
Load balancing of log servers. Support for load balancing of external log servers for preventing storage of redundant log messages.
-
Minimal Logging. Deterministic LSN configurations or Dynamic LSN configurations with port block significantly reduce the large scale NAT64 log volume.
-
Logging MSISDN information. Support for including subscribers' MSISDN information in large scale NAT64 logs to identify and track subscriber activity over the Internet.
-