Re: issue 3: nat traversal
"Mohan Parthasarathy" <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <018601c4dbd8$962e92b0$861167c0@adithya> |
> > > The issue is a bit confusing to me. I agree that we don't want to modify > > the IKEv2 NAT traversal as specified in the IKEv2 draft. But do we want > > MOBIKE to work when moving behind NATs ? I am not sure which > > question is being asked here. > > I think the key question is what do we want MOBIKE to do, > i.e., does it need to work when moving behind a NAT? And > then answer seems to be yes. > Okay. Do we want to add the qualifier that MOBIKE needs to work in a "secure" fashion when moving behind a NAT ? (unlike IKEv2 which also supports NAT traversal but susceptible to 3rd party bombing attacks). > Its true that the we have a restriction that we should not modify > IKEv2 NAT traversal. My advice is not to focus too much on this > question. Lets do what it makes technical sense. I do not think > any of the current proposals modify NAT-T, even if we can perhaps > provide a new stage in the protocol when it is turned on (not just > in the initial contact). So lets not worry about this part. > Note that none of the current proposals support NAT traversal. >From what i have read, they only have a prevention mechanism. -mohan > --Jari > _______________________________________________ > Mobike mailing list > [email protected] > https://www.machshav.com/mailman/listinfo.cgi/mobike