Microsoft RickRolls Wi-Fi leechers at TechEd
techedbackstage.net
techedbackstage.net
Interestingly, they did not not see this as a flaw in the Windows kernel. You can get a data structure which allows 2^48 concurrent connections by NAT on a single IP address if you map based on (destination IP address,port) rather than just (port).
OpenBSD does this, to avoid the very problem these Microsoft people solved by complex tools and a rick roll.
But if you think I'm taking a position, please explain. (I'm reminded of Herman Melville reacting to various academic's analysis of symbolism in Moby Dick. Something to the effect that he didn't know that stuff was in there!) Unjustified projection of fictional intention is just as cheap as putting words into another's mouth.
[edit: my comment on that page asking about this hasn't been answered, but there's a reply to another comment saying "people were approached" that refers to the previous post - http://www.techedbackstage.net/2010/02/17/bittorrent-traffic... - that does describe in more detail what happened. and there's still no description of a general announcement.
i do understand their frustration, but to take an approach like this without any announcement is going to encourage some people to "fight back". a sympathetic announcement with an explanation would have got the majority of users "on their side", producing peer pressure and setting expectations that would reduce the amount of conflict. not doing so comes across as passive aggressive and encourages an "arms race"]
Of course asking people to stop, explaining why stopping would fix the network problems and stating abusers will get kicked are the correct first step just to let people know what's going on.
I'd hope a competent network admin would have seen this (bit torrent abuse and nat port exhaustion) coming from miles and miles away.
<facepalm> Why exactly did they gloss over this as if it was no big deal? </facepalm>
The way that I see it they should either:
1) Fix RRAS to use all IPs in the public address pool.
2) Fix ipnat.sys to use a lookup table that keys on external_destination_ip+port rather than just port.
3) Make an announcement that several users are abusing the network with excessive BitTorrent usage which is taxing the NAT. State that BitTorrent users will be kicked from the network if the situation does not improve.
4) Make an announcement asking BitTorrent users to limit the total number of ports their client is using. Most BitTorrent clients (even rtorrent) allow you to limit the number of connections on a global or per-torrent basis. There really is no reason that one needs to have upwards of 800 (or even 2500) ports at a given time.
In general, #1 and #2 should be done anyways regardless of how they solved the immediate situation at the conference.
Certainly, after paying to attend the conference I'd feel entitled to some bandwidth as well. If the network is using a poor NAT implementation, that's negligent network planning and the admins should shoulder the blame instead of screwing with the users.
I've heard that one before! (Not that they don't actually have those problems in India)
Why the snarky comments, HNers?
Pointing out where anyone called Microsoft evil or a monopoly on this page would be helpful as well.