Re: issue 3: nat traversal

Francis Dupont <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   > what is a "secure" nat traversal solution for you? 

   The one that does not have the 3rd party bombing attack :-)
   To put in a different way, MOBIKE's security should not
   be altered, when moving behind a NAT. As we are
   at the design stage, it might make sense to understand
   what sort of NAT traversal solution we are going to
   have. 
   
=> to avoid the intrinsic security issue (i.e., the 3rd party
bombing attack) of NAT traversal is very hard, and IMHO impossible
without modifying NATs and/or NAT traversal.

   > > Note that none of the current proposals support NAT traversal. 
   > > From what i have read, they only have a prevention mechanism.

=> NAT prevention is important for security as I explained in a previous
message, and it "solves" the NAT traversal problem too.
IMHO we should only give the choice between NAT traversal and MOBIKE,
i.e., MOBIKE should only detect the "just move behind a NAT" case,
and should *not* try to handle it (i.e., the case will be considered
as misconfiguration).

Regards

[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.