Re: RR checks to avoid DoS attacks (summary)
"Dondeti, Lakshminath" <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Hi all, Bill and Michael argue that a malicious IPsec client can trick a remote access server to forward a high volume stream to a third party entity, thus launching a DoS attack. I made the case that RR checks should be optional in the interest of minimal signaling, and considering that the above DoS attack is implausible, for the attack is too costly/risky for the attacker, and because there are a lot of easier avenues to launch similar attacks, which (looking into my crystal ball here) will be around for a long time to come. Bill and Michael say that the attack is quite feasible and therefore RR is a MUST. I hope not, I tend to roam a lot withing the building I work in and would like my laptop to download my email, not do RR checks. cheers, Lakshminath