Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revision | |||
en:dpi:opt_cgnat:abuse_letters:start [2024/03/15 09:02] – elena.krasnobryzh | en:dpi:opt_cgnat:abuse_letters:start [Unknown date] (current) – removed - external edit (Unknown date) 127.0.0.1 | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | {{indexmenu_n> | ||
- | ======Working with NAT Flow. How to find a subscriber after NAT====== | ||
- | <note tip>The following components are required for this functionality to work: [[en: | ||
- | Description for configuring NAT in QoE: [[en: | ||
- | =====Example of working with abuse letters===== | ||
- | |||
- | This tutorial is how to find the specific subscriber who is reported abuse.\\ | ||
- | The abuse email usually contains a global address from a NAT pool. We need to understand which of the subscribers went to the resource where the virus activity was detected at a known time behind this NAT-pool.\\ | ||
- | We need to perform **two steps** — find the necessary information in the abuse email and use it to identify the subscriber in the GUI of the Stingray. | ||
- | |||
- | ====Step 1. Research the email==== | ||
- | - The address from your NAT pool (source IP). | ||
- | - Address of the attacked resource (destination IP) | ||
- | - Activity time on the attacked resource // | ||
- | |||
- | * **Example 1.** \\ {{dpi: | ||
- | |||
- | * ** Example 2.** \\ {{dpi: | ||
- | |||
- | More can be found useful in the email: | ||
- | - Reason of abuse \\ {{dpi: | ||
- | - History of abuse (if the activity was repeated) \\ {{dpi: | ||
- | |||
- | This can help you understand the scope of the problem and identify similar problems on your network. | ||
- | |||
- | ====Step 2. Looking for subscriber activity in the GUI==== | ||
- | The task is to determine from the logs which subscriber behind the NAT-pool (source IP) specified in the letter was accessing the destination IP at that time. | ||
- | |||
- | Before you start the search it is worth checking two facts: | ||
- | - The NAT pool in question is set to CG-NAT in Stingray. \\ {{dpi: | ||
- | - The NAT log storage time captures the time of activity. View and configure \\ {{dpi: | ||
- | |||
- | Then in the GUI you need to open the section NAT flow, select a period, enter the source and destination IP. \\ | ||
- | * {{dpi: | ||
- | |||
- | * {{dpi: | ||
- | < |