Re: issue 3: nat traversal
Jari Arkko <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Organization | None |
| Message-ID | <[email protected]> |
Mohan Parthasarathy wrote: >>>Okay. Do we want to add the qualifier that MOBIKE needs to >>>work in a "secure" fashion when moving behind a NAT ? >>>(unlike IKEv2 which also supports NAT traversal but >>>susceptible to 3rd party bombing attacks). >> >>what is a "secure" nat traversal solution for you? >> > > The one that does not have the 3rd party bombing attack :-) > To put in a different way, MOBIKE's security should not > be altered, when moving behind a NAT. As we are > at the design stage, it might make sense to understand > what sort of NAT traversal solution we are going to > have. Right. And I want MOBIKE to be secure in this fashion. However, if we move behind a NAT, and our configuration allows such move, I think we pretty much have to downgrade the security to what NAT-T offers. Or do you see a way around that? --Jari