a different perspective on NAT
"Eric S. Johansson" <[email protected]>
| Newsgroups | gmane.comp.audio.speak-freely.general |
|---|---|
| Message-ID | <[email protected]> |
folks seem to be living a bit of a fantasy in that if we somehow magically
migrated to IPv6, all of a sudden applications like speak freely or BitTorrent
would somehow work without interference. I will argue that no matter what
version of IP we use, security perimeter measures be it a traditional subnet
firewall or firewall plus address translation, will still be impediments to
peer-to-peer protocols. Instead, I think we should be focused on the
development of some mechanism allowing peer-to-peer services to transit
firewalls in a "safe" manner. Ideally this is something that should happen
automatically without requiring any application change but obviously that might
not be possible. We also need to consider that it may be impossible to do any
form of tunneling or pinholing safely and maybe we need to look at a different
protocol infrastructure that can be distributed. For example, proxy by CGI on a
Web service "owned" by a end-user.
Another thing to consider is that speak freely is being replaced by SIP and that
may be the effort should be put into embedding SSL into SIP. Also, like speak
freely, SIP has its challenges with address translation boundaries when trying
to communicate peer-to-peer. I'm currently a member of the free world dial-up
network and I need to use their proxy when making calls.
just a couple of thoughts.
---eric
* * *
To unsubscribe from this mailing list, send E-mail containing
the word "unsubscribe" in the message body (*not* as the
Subject) to [email protected]