Re: Mobile IP and Mobike
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- >>>>> "James" == James Kempf <[email protected]> writes: James> think it would be a good idea in any event to design MOBIKE James> so that it works this way. Typically, people use a VPN into James> a corporate network because they also want to derive the James> benefits of firewall support for external access, not simply James> to access hosts within the corporate LAN. Most client side "Typical" for Windows clients, true. Virus+remove-attack risk exceeds any benefit from route optomization. Untypical for everyone else, including PDAs and other things. James> From a technical standpoint, I also don't see why the host James> would need to use its local address when contacting hosts James> outside the corporate network. The local address is changing, James> but the address in the corporate network presumably isn't, James> or, at least, I can't see any reason why it should. So it I do this all the time, as do my colleagues. We use the local address on the inside of peer-to-peer tunnels for things like SIP. All of our machines have globally unique public IPs for use inside their tunnels, and that is how we configure customer machines. This is because we have a more sophisticated IPsec policy ability. Please do not assume that the limits of current IP-Telco RemoteAccess systems define what future usage is. That's why we spent the 1980s and early 1990s working *around* the Telcos. ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Xelerance Corporation, Ottawa, ON |net architect[ ] [email protected] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) Comment: Finger me for keys iQCVAwUBQZTh/oqHRg3pndX9AQEc+QQAhkEAgGnSt7xmXYX2724zdTGOWPorgv8L o+mMk9krXzMtG3SnnqSNJ6wKav3e5hVSpemwirP6yvwlC2ocUqi8eGbK/AumDH85 e1ikzkyTlIMfiNzsexpa35di9zXkEwKhGZ1kC+HNlqwuY9iweKZLRfTxNsacocPI e1YsjF+RMoc= =hvJf -----END PGP SIGNATURE-----