Re: [Fwd: I-D ACTION:draft-jennings-midcom-stun-results-00.txt]

Jonathan Rosenberg <[email protected]>
Newsgroups gmane.ietf.midcom
Organization dynamicsoft
Message-ID <[email protected]>

Jiri Kuthan wrote:

> At 04:24 AM 2/18/2004, Yutaka Takeda wrote:
> 
>>>With ICE, a UAS will first check connectivity to UAC's STUN address.
>>>The ICE draft suggests doing so on the initial application request
>>>(SIP INVITE e.g.) to keep call set up time low. At this 
>>>moment however, 
>>>UAC's NAT is not primed yet and the STUN check reports no 
>>>connectivity.
>>
>>My understanding is that the connectivity check is done at the same time
>>at both ends. 
> 
> 
> I am not sure ICE is now suggesting UAC's connectivity checks 

Yes, ICE has both sides doing checks.

> and I still see 
> race conditions potential in the call flow. For example, UAS may get ICMP errors 
> for the connectivity checks before UAC receives 183 and primes its NAT with its 
> connectivity checks. 

My understanding is that most NATs do not generate ICMP if you hit 
unallocated ports, as it would facilitate port scans. However, if this 
is a real concern, its easily addressed by simply mandating the checks 
on the uas side get done over some duration so that you are sure they 
really have failed.

Are there other race conditions you know of?

-Jonathan R.


-- 
Jonathan D. Rosenberg, Ph.D.                600 Lanidex Plaza
Chief Technology Officer                    Parsippany, NJ 07054-2711
dynamicsoft
[email protected]                     FAX:   (973) 952-5050
http://www.jdrosen.net                      PHONE: (973) 952-5000
http://www.dynamicsoft.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.