RE: Some extensions to STUN.
"Christian Huitema" <[email protected]>
| Newsgroups | gmane.ietf.midcom |
|---|---|
| Message-ID | <DAC3FCB50E31C54987CD10797DA511BA0246F2EF@WIN-MSG-10.wingroup.windeploy.ntdev.microsoft.com> |
> One is testing to see if they rewrite data inside the payload of a UDP > packet. NATs have been observed that rewrite the mapped address inside the > stun packet. Multiple people have suggested a solution to this - an > extension that returned an encrypted (mostly likely with xor) form of the > the mapped address with some predefined key would detect this. We did observe that behavior in some NATs during the testing of Teredo, and incorporated an XOR protection in Teredo. I suggested to incorporate the same fix in STUN, but I was overruled by my co-authors. -- Christian Huitema