design draft issue: nat-p

Jari Arkko <[email protected]> Wed, 21 Dec 2005 12:51:56 +0200
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
>   This gives extra
>    protection against 3rd party bombing attacks (the attacker cannot
>    divert the traffic to some 3rd party). 


This seems inaccurate, or at least too strong. We have
other mechanisms to prevent that, and the NAT-T based
attack only works for on-path attackers. Just say
"This avoids any possibility of on-path attackers modifying
addresses in headers" and refer to Francis's pseudonat
attack draft.

--Jari