D106 design draft issue: nat-p

Tero Kivinen <[email protected]> Tue, 3 Jan 2006 18:38:02 +0200
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
[issue list: http://www.kivinen.iki.fi/ietf/mobike-design-issues.html
 working copy of document:
 http://www.kivinen.iki.fi/ietf/draft-ietf-mobike-design-06.txt]

Jari Arkko writes:
> >   This gives extra
> >    protection against 3rd party bombing attacks (the attacker cannot
> >    divert the traffic to some 3rd party). 
> 
> 
> This seems inaccurate, or at least too strong. We have
> other mechanisms to prevent that, and the NAT-T based
> attack only works for on-path attackers. Just say
> "This avoids any possibility of on-path attackers modifying
> addresses in headers" and refer to Francis's pseudonat
> attack draft.

Why do you think that NAT-preventation does not protect against 3rd
party bombing attacks?

If we do put all IP addresses used inside the packets, and
cryptographically integrity protect them, and we enable NAT
preventation, which means we do not allow NATs, how can attacker
divert the traffic to some 3rd party?
-- 
[email protected]