Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Kinda OT, iChat AV behind NATed firewalls




On Jan 31, 2005, at 5:59 AM, Admin wrote:

i'll keep this short as its not really on topic.

I want to have isight / iChat between two sites, multiple
connections simultaneously, can't port forward
as that 1-1, firewall supports SIPS, but does iChat?

I will get a site-site VPN up at some point, but for
now.. is there a way??????


afaik, as long as the NAT does consistent port translation, you can do iChat AV sessions even if both peers are behind NAT. There is a handy utility called natcheck which can help you determine if your NAT devices are p2p friendly in this respect.


http://midcom-p2p.sourceforge.net/

Here's a binary I built in 10.3.7 that you can download if you don't have access to a compiler.
http://www.dreness.com/bits/tech/natcheck


Note that the GUI version linked on that site won't work in panther.

Running the command line version looks something like this:

andre@gyro[~/work]natcheck -v
server 1: pdos.lcs.mit.edu at 18.26.4.9:9856
server 2: tears.lcs.mit.edu at 18.26.4.77:9856
server 3: sure.lcs.mit.edu at 18.26.4.29:9856
Local TCP port: 54887
Local UDP port: 53315
Request 1 of 20...
Connection to server 1 complete
Connection to server 2 complete
Server 2 reports my UDP address as 216.254.1.99:35828
Server 1 reports my UDP address as 216.254.1.99:35828
Server 3 reports my UDP address as 216.254.1.99:35828
Server 1 reports my TCP address as 216.254.1.99:35826
Connection from 18.26.4.29:9856
Server 3 reports my TCP address as 216.254.1.99:35826
Request 2 of 20...
Loopback packet from 216.254.1.99 port 35830
Server 1 reports my UDP address as 216.254.1.99:35828
Server 2 reports my UDP address as 216.254.1.99:35828
Server 3 reports my UDP address as 216.254.1.99:35828
Request 3 of 20...
Loopback packet from 216.254.1.99 port 35830
Server 1 reports my UDP address as 216.254.1.99:35828
Server 2 reports my UDP address as 216.254.1.99:35828
Server 3 reports my UDP address as 216.254.1.99:35828
Request 4 of 20...
Loopback packet from 216.254.1.99 port 35830
Server 1 reports my UDP address as 216.254.1.99:35828
Server 2 reports my UDP address as 216.254.1.99:35828
Server 3 reports my UDP address as 216.254.1.99:35828
Request 5 of 20...
Loopback packet from 216.254.1.99 port 35830
Server 2 reports my UDP address as 216.254.1.99:35828
Server 1 reports my UDP address as 216.254.1.99:35828
Server 3 reports my UDP address as 216.254.1.99:35828
Server 2 reports my TCP address as 216.254.1.99:35826
Connection already accepted from server 3
Initiated TCP loopback connection
Connection from 216.254.1.99:35832
Loopback received
... (snip) ...
Request 20 of 20...
Loopback packet from 216.254.1.99 port 35830
Server 1 reports my UDP address as 216.254.1.99:35828
Server 2 reports my UDP address as 216.254.1.99:35828
Server 3 reports my UDP address as 216.254.1.99:35828

TCP RESULTS:
TCP consistent translation:           YES (GOOD for peer-to-peer)
TCP simultaneous open:                YES (GOOD for peer-to-peer)
TCP loopback translation:             YES (GOOD for peer-to-peer)
TCP unsolicited connections filtered: NO  (BAD for security)

UDP RESULTS:
UDP consistent translation:           YES (GOOD for peer-to-peer)
UDP loopback translation:             YES (GOOD for peer-to-peer)
UDP unsolicited messages filtered:    NO  (BAD for security)
andre@gyro[~/work]

-Andre

thanks.

_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/macos-x-server/ email@hidden


This email sent to email@hidden

_______________________________________________ Do not post admin requests to the list. They will be ignored. Macos-x-server mailing list (email@hidden) Help/Unsubscribe/Update your Subscription: http://lists.apple.com/mailman/options/macos-x-server/email@hidden

This email sent to email@hidden
References: 
 >Kinda OT, iChat AV behind NATed firewalls (From: Admin <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.