RE: issue 3: nat traversal
Tschofenig Hannes <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
hi mohan, thanks for your feedback. please see my comment below: ~snip~ > Okay. Do we want to add the qualifier that MOBIKE needs to > work in a "secure" fashion when moving behind a NAT ? > (unlike IKEv2 which also supports NAT traversal but > susceptible to 3rd party bombing attacks). what is a "secure" nat traversal solution for you? > > > Its true that the we have a restriction that we should not modify > > IKEv2 NAT traversal. My advice is not to focus too much on this > > question. Lets do what it makes technical sense. I do not > think any of > > the current proposals modify NAT-T, even if we can perhaps > provide a > > new stage in the protocol when it is turned on (not just in the > > initial contact). So lets not worry about this part. > > > Note that none of the current proposals support NAT traversal. > From what i have read, they only have a prevention mechanism. > i got a different impression. see for example, - <draft-eronen-mobike-simple-00.txt> - <draft-eronen-mobike-mopo-01.txt> ciao hannes > -mohan > > > --Jari > > _______________________________________________ > > Mobike mailing list > > [email protected] > > https://www.machshav.com/mailman/listinfo.cgi/mobike >