Re: Issue 60: Addresses in IKE_SA_INIT/AUTH (was: Comments of draft-ietf-mobike-protocol-04.txt)
Jari Arkko <[email protected]> Sun, 23 Oct 2005 13:48:38 +0300
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Having read through this thread, I tend to agree with Pasi on this, i.e., take the addresses from where they are currently taken from and use NO_NATS_ALLOWED where its currently in. I do not think the leakage of addresses is an issue, and if it is, we are already doing it in ADDITIONAL_*_ADDRESS. The rest of the issue is really a debate about aesthetics and complexity of variant 1 or variant 2; personally I think what's in the document right now seems better. Here's a suggested addition to the Security Considerations, Section 6.5, after the fourth paragraph: The use of NO_NATS_ALLOWED will also disclose the internal address to the peer, in case NAT was in the path. However, this has relevance only if the node is configured to first try with NO_NATS_ALLOWED and only then fallback to the use of NAT traversal if that fails. --Jari