design draft issue: nat-p
Jari Arkko <[email protected]> Wed, 21 Dec 2005 12:51:56 +0200
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
> This gives extra > protection against 3rd party bombing attacks (the attacker cannot > divert the traffic to some 3rd party). This seems inaccurate, or at least too strong. We have other mechanisms to prevent that, and the NAT-T based attack only works for on-path attackers. Just say "This avoids any possibility of on-path attackers modifying addresses in headers" and refer to Francis's pseudonat attack draft. --Jari