Re: Issue 60: Addresses in IKE_SA_INIT/AUTH (was: Comments of draft-ietf-mobike-protocol-04.txt)
<[email protected]> Mon, 14 Nov 2005 15:58:32 +0200
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Tero Kivinen wrote: > > Actually sending UNEXPECTED_NAT_DETECTION during IKE SA creation > is quite useless, as it cannot be authenticated, and also if the > initiator wants to ignore those error notifications and continue > retrying regardless of them. So why do we send those notifies in > the first place? Hmm, this is true:if there's an attack, we cannot really detect it at the IKE_SA_INIT stage anyway.... So as I already said in the meeting last week, I've changed my opinion and support your proposal (take addresses from 1st IKE_AUTH exchange, NAT-T or no NAT-T). Best regards, Pasi