Guides

What happens when NAT logs are asked for and cannot be produced?

The reply takes one paragraph to write. Everything that follows it happens outside your network, to your customers, to your address ranges, and to the way the next request is worded.

You send back a short statement saying the records do not exist, and that statement becomes part of the file. The question does not disappear with it. It moves to whoever else can be asked, the search continues with whatever names are within reach, and your network is now the part of the story that has to be explained.

What can an operator actually say when the record is not there?

Only one of three things, and all three describe your own network rather than the incident. Either nothing of that kind was ever collected, or something was collected that does not reach far enough to answer, or something was collected and no longer exists. Each is a sentence about how you run a network, written by you, kept by somebody else.

The reply itself is unremarkable to write.

Your reference 4417, request for subscriber details Against the address, port and period given, we hold no records covering that period and are unable to identify the subscriber concerned.

What makes it consequential is that it is a statement of fact about your operation, given in writing, by somebody with authority to give it. It sits in a file next to the same statement from every other network that was asked something similar, and it is read again the next time your name comes up.

Three ways of being unable to answer, and where each one leads
The position you are inWhat you can honestly sayWhat tends to follow
Nothing of this kind was collected The network does not keep a record of translations It reads as a decision rather than an accident, and the next exchange begins with why
Something was collected, but it stops short Records exist, and they do not narrow to one subscriber You are asked to send what you have anyway, and it names a group of customers
It was collected and is gone The period asked about falls outside what is still held The conversation turns to how long you keep things, and who chose that

The middle row is the one operators land in most often and expect least. Partial records feel like a defence while they are being described and read as an admission once they are on paper, because they show that the traffic passed through you and that you cannot say through whom.

Where does the question travel once you have said no?

Sideways, and then back to you. The request belongs to a case with its own timetable and its own people, so a reply that closes nothing simply moves the same question along to whoever else stood in the path of that traffic.

Usually that means the network above you. Your upstream can show which of its customers held the address at the time, and the answer to that is your name, so the enquiry arrives a second time with more context and less patience. Where the traffic ended at a large platform, that platform gets asked as well, and platforms tend to hold precise records of what reached them.

The same incident then reappears at intervals, worded slightly differently, as a case passes between the people working it. Answering the same question three times over a year is a normal outcome of having been unable to answer it once.

Preservation notices are the uncomfortable version. One arrives asking you to hold everything relating to a period, and you have to reply that there is nothing to hold, which converts a routine instruction into a second piece of correspondence about how your network is run.

Why does the search move on to the nearest name it can find?

Because an investigation does not pause for want of a record. It continues with whatever is available, and what is available is usually the account standing closest to the address.

Where one external address serves a few hundred homes, the address alone points at all of them. Strip out the detail that separates one household from the rest and you leave a list, and somebody working from that list picks the most plausible entry. Courts have refused to let names be attached to addresses on that basis, pointing at searches carried out at houses whose connections had been used by someone else entirely.

Those households are your customers. When one of them is questioned over traffic they did not generate, they come to you to be cleared, and the same gap that stopped you naming the right subscriber stops you clearing the wrong one. An absent record does not merely fail to identify. It fails to exonerate, and the second failure lands on the person paying you.

Every other party in the chain, meanwhile, keeps a complete account of what they saw. Servers on the public internet are advised to record the source port along with the address for exactly this reason, and that is why the port arrives in the request in the first place. When the question is precise and the answer is vague, the vagueness is attributed to you.

What does a network that cannot answer look like from outside?

Like somewhere consequences do not follow behaviour. That reputation forms quickly, spreads through channels you have no access to, and is slow to reverse once it exists.

It starts at your abuse mailbox. Reports arrive naming an address and a moment, you cannot resolve either to a customer, and nothing is done. Spamhaus puts the mechanism plainly: a problem that cannot be identified does not get fixed. The listing that follows attaches to the range rather than to the customer who earned it, so every other subscriber on that range carries it, and delisting requires you to describe how the problem was stopped, which you cannot do without knowing who caused it.

Your upstream sees the same reports. Transit providers and peers keep their own view of which networks generate complaints and which of them respond, and that view shapes commercial conversations you would rather have on other grounds.

There is also a standard to be measured against, and it is not a regulator's. The IETF best current practice for carrier grade NAT sets out what a shared address deployment needs to write down for each mapping it creates: the transport protocol, an identifier for the subscriber, the external source address, the external source port, and a timestamp. That list is the industry's own answer to this question, published by the people who designed address sharing. European law enforcement went further and said in public that the great majority of mobile access providers had deployed address sharing in a way that left them unable to identify individual subscribers when required to.

What does this cost inside the business?

Time first, in the least useful shape. Somebody spends two days establishing that a thing does not exist, then somebody more senior reads the letter, drafts the reply and signs it, and none of that work leaves anything behind for next time.

Deadlines make it worse. These requests carry one, and the search starts under it, which is how people end up pulling apart a production router on a working afternoon to check whether anything was ever written anywhere.

The commercial edge shows up later and further from the network. Corporate contracts, public sector tenders and wholesale arrangements ask what you keep and for how long, and by then the honest answer is on file in your own words. Nobody rejects a bid over log retention alone, and it becomes one more reason among several.

Then the same thing gets bought anyway, under time pressure, chosen quickly and installed in whatever state the network is in. The cost was never avoided. It was deferred until the least convenient moment and paid with an audience.

Is there anything to be done once the window has closed?

For that request, nothing. A translation that was not written out leaves no trace once the router has moved past it, and no amount of care afterwards recovers it. What can be changed is the position you will be in when the next one arrives, and there will be a next one.

Start with precision about your own position. A reply that states exactly what you hold, and from when, closes the exchange. A vague one invites a follow up asking you to be specific, and the follow up gets answered by somebody with less context than you had.

Then close the gap that produced the silence, beginning wherever it is widest. Most networks find that the first fix is unglamorous and cheap compared to the correspondence it prevents.

The variable you control is the date the record begins. Every day it does not exist is a day that stays permanently unanswerable, whoever asks and however good the reason. That is the whole argument, and it does not get better with waiting.

Does replying that you hold no records end the matter?

No. The reply is filed and the same question is put to whoever else sits in the path, which often means your upstream provider. Requests about one incident come back more than once as a case moves between people.

Can a public IP address on its own identify a subscriber?

Not where the address is shared. On its own it points at everybody translated through it during that period. Courts have declined to treat an address by itself as identification, citing searches that landed on the wrong household.

What does the industry expect a shared address setup to record?

The IETF best current practice for carrier grade NAT, BCP 127, lists the transport protocol, a subscriber identifier, the external source address, the external source port and a timestamp for each mapping created.

Can missing NAT records be reconstructed after the fact?

No. A translation that was never written out leaves nothing behind once the router has moved on. Billing, tickets and traffic graphs describe volume and accounts, not which subscriber held which external port at a given second.

Could you answer one today?

Tell us what you keep now, and how far back, and we will say plainly what that would answer.

Request a quote