Re: Issue 60: Addresses in IKE_SA_INIT/AUTH (was: Comments of draft-ietf-mobike-protocol-04.txt)

Jari Arkko <[email protected]> Sun, 23 Oct 2005 13:48:38 +0300
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Having read through this thread, I tend to agree with
Pasi on this, i.e., take the addresses from where they
are currently taken from and use NO_NATS_ALLOWED
where its currently in.

I do not think the leakage of addresses is an issue, and
if it is, we are already doing it in ADDITIONAL_*_ADDRESS.
The rest of the issue is really a debate about aesthetics
and complexity of variant 1 or variant 2; personally I think
what's in the document right now seems better.

Here's a suggested addition to the Security Considerations,
Section 6.5, after the fourth paragraph:

The use of NO_NATS_ALLOWED will also disclose the
internal address to the peer, in case NAT was in the path.
However, this has relevance only if the node is configured to first
try with NO_NATS_ALLOWED and only then fallback to
the use of NAT traversal if that fails.

--Jari