Guides

Written for people who run the network rather than read about it. Each one takes a single question and stays on it until there is nothing left to say.

These are working notes rather than articles. They come from setting this up on real networks, so they spend their time on the parts that catch people out instead of the parts that are easy to describe. New ones go up as they are written.

01 How does NAT logging work on a MikroTik router? What gets written down at the moment an address is rewritten, where it goes from there, and the five faults that stop it silently. 02 What is NAT log management, and why does it matter for an ISP? The work that starts after the router sends a line. What a request for records asks for, and what has to already be in place to answer it. 03 How do you read a raw NAT syslog line, field by field? The envelope, the protocol variations, the shapes that resemble a translation record without being one, and how to watch your own router live. 04 What mistakes do ISPs make with NAT logging? The failures that only show up when a record is asked for. Logging at one point, retention by accident, and sizing for the subscriber count you used to have. 05 How do you attach a PPPoE username to a NAT record? A NAT line names an address, not a person. What you match it against, and why the moment on the clock decides the answer more than the address does. 06 What happens when NAT logs are asked for and cannot be produced? The reply is one paragraph. Where the question goes afterwards, why the search lands on the nearest name, and what it does to your address ranges. 07 How do you find the subscriber behind a public IP and port? One shared address, one port and one moment, turned into a named account. The four stages, and the errors that hand back a confident wrong name. 08 What does an ISP gain from keeping NAT logs properly? Answering a request is one gain out of several. What these records give you in abuse handling, capacity and disputes, and what they will not do. 09 Why does sharing one public IP between subscribers make tracing hard? How many customers fit behind one address, what the sharing takes away from a record, and why a port number stops being unique within minutes. 10 What logging should a new ISP have in place from the first day? What to switch on while the network is still empty, and the single decision that no later effort can put right. 11 How do you keep only the NAT records out of everything syslog sends? A router sends its whole diary. Where to filter, what each place costs you, and the stream people cut first that they cannot answer anything without. 12 What does running a log server actually cost? Which costs hold still, which follow the customer count, what a gap in collection costs, and how to tell whether the whole thing pays for itself. 13 Why do duplicate NAT log lines appear, and what do they cost? One connection written down forty times. Where the repetition comes from, how to tell it from two real connections, and whether it can be cleaned up. 14 Should you build your own NAT log server or buy one? The first version takes a weekend. What the work actually contains after that, and the three things worth asking a supplier before buying instead. 15 How much storage does NAT logging need, and how do you work it out? Four numbers multiplied together. Which you can look up, which has to be measured on your own network, and what to add before buying a disk.

Rather not work it out from scratch?

Tell us about your network and we will say plainly what it would take.

Request a quote