NAT Mapped Address Reachability Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network Address Translation (NAT) systems face challenges in maintaining effective connectivity due to issues like misconfigured access control lists and external blacklisting, which can lead to unnoticed connectivity problems for internal clients, especially when using Port Address Translation (PAT), making it difficult to troubleshoot and support.

Innovation Solution

Implementing a system that continuously monitors the reachability status of NAT pool IP members by tracking connection success and failure rates to selectively assign network address translated mapped addresses based on their prior network reachability, providing administrative notifications when issues are detected, and dynamically managing the use of mapped addresses to ensure optimal connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If NAT systems use large pools of public IP addresses to service internal clients, then address space utilization is improved, but connectivity reliability deteriorates due to misconfigured access control lists and external blacklisting

Engineering Contradiction:
Improvenumber of mapped addressesVSAvoidconnectivity reliability
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system performs preliminary reachability testing on mapped addresses before assigning them to internal clients. Connection test packets are sent to external destinations to verify accessibility, and only addresses that pass these tests are added to the available pool. This prevents assignment of addresses that are already blacklisted or blocked by access control lists, thereby maintaining high connectivity reliability while utilizing large address pools.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors connectivity status of mapped addresses by sending test packets and tracking success/failure rates. When a mapped address shows connectivity failures (indicating blacklisting or access control list blocking), the system receives feedback and automatically removes that address from the available pool. This closed-loop feedback mechanism ensures that unreliable addresses are promptly identified and excluded, maintaining overall system reliability.

Inventive Principle:
Principle #23Feedback

2Device complexity

If NAT systems assign mapped addresses without monitoring reachability, then system complexity is reduced, but troubleshooting difficulty increases due to unnoticed connectivity problems

Engineering Contradiction:
Improvesystem complexityVSAvoidtroubleshooting difficulty
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The NAT system performs self-diagnosis by automatically sending connection test packets to external destinations using each mapped address. The system independently monitors its own connectivity status, detects blacklisting or access control list blocking, and self-corrects by removing problematic addresses from the available pool. This self-service approach enables the system to detect and respond to connectivity issues without external intervention, reducing troubleshooting difficulty while maintaining manageable complexity through automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback monitoring by tracking connection success and failure rates for each mapped address. When failures exceed a threshold, the system automatically generates alerts and removes the problematic address from service. This automated feedback loop enables early detection of connectivity issues before they affect internal clients, significantly reducing troubleshooting difficulty while the modular implementation keeps system complexity acceptable.

Inventive Principle:
Principle #23Feedback

3Reliability

If NAT systems continuously monitor reachability status of all mapped addresses, then connectivity reliability is improved, but computational overhead increases

Engineering Contradiction:
Improveconnectivity reliabilityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies partial monitoring by continuously testing only a subset of mapped addresses rather than all addresses. Connection test packets are sent to a representative sample of external destinations, and reachability status is updated based on these partial tests. This approach provides sufficient connectivity reliability assurance while significantly reducing computational overhead compared to testing every single mapped address continuously.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs reachability monitoring at periodic intervals rather than continuously for all addresses. Connection tests are conducted at scheduled times, and the frequency can be adjusted based on network conditions and requirements. This periodic approach maintains connectivity reliability by regularly detecting issues while reducing computational overhead by allowing idle periods between tests, thereby balancing reliability requirements with resource constraints.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9667595B2Selectively using network address translated mapped addresses based on their prior network reachability
Publication Date: 2017.05.30 CISCO TECHNOLOGY INC
  • US9667595B2 patent drawing
  • US9667595B2 patent drawing
  • US9667595B2 patent drawing

AI summary

In one embodiment, network address translated (NAT) mapped addresses are selectively used based on their prior network reachability. One embodiment maintains for each particular mapped address (e.g., NAT public address pool member), a reachability status level based on prior usage of the particular mapped address to communicate with external destinations. By continuously monitoring the reachability “health” of mapped addresses, problem-experiencing mapped addresses can be avoided. One embodiment monitors the success and/or failure rates of connection attempts over a rolling time period to provide an up-to-date current view of the reachability status level of corresponding mapped addresses. In one embodiment, a network address translation device assigns, based on their reachability status level, these mapped addresses. One embodiment provides an administrative notification for particular mapped address or ceases using the particular mapped address in response to its reachability status level falling outside a predetermined or calculated level.