-
Notifications
You must be signed in to change notification settings - Fork 6
Open
Labels
area/natRelated to Network Address Translation (NAT)Related to Network Address Translation (NAT)enhancementNew feature or requestNew feature or request
Milestone
Description
In stateful (source) NAT, a distinct port allocator should be kept per:
- src-ip
- dst-ip
- protocol
- dst-port
- dst-vpcid
Currently, the dst-ip and dst-port are not considered. This means that we limit the number of ports (and hence possible flows) between one or more vpcs trying to "connect" to some "serving" VPC without considering that the serving vpc may expose the service over multiple ip addresses and ports, which would allow it to scale nearly endlessly.
see #1098
Metadata
Metadata
Assignees
Labels
area/natRelated to Network Address Translation (NAT)Related to Network Address Translation (NAT)enhancementNew feature or requestNew feature or request