Re: issue 3: nat traversal
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote: > what is a "secure" nat traversal solution for you? The one that does not have the 3rd party bombing attack :-) To put in a different way, MOBIKE's security should not be altered, when moving behind a NAT. As we are at the design stage, it might make sense to understand what sort of NAT traversal solution we are going to have. => to avoid the intrinsic security issue (i.e., the 3rd party bombing attack) of NAT traversal is very hard, and IMHO impossible without modifying NATs and/or NAT traversal. > > Note that none of the current proposals support NAT traversal. > > From what i have read, they only have a prevention mechanism. => NAT prevention is important for security as I explained in a previous message, and it "solves" the NAT traversal problem too. IMHO we should only give the choice between NAT traversal and MOBIKE, i.e., MOBIKE should only detect the "just move behind a NAT" case, and should *not* try to handle it (i.e., the case will be considered as misconfiguration). Regards [email protected]