RE: issue 1: direct or indirect indicators

Tschofenig Hannes <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
hi francis,

please see my comment below:

>  In your previous mail you wrote:
> 
>    >  In your previous mail you wrote:
>    > 
>    >    a separate question but also of interest: 
>    >    - should a peer send an address list in one message or 
>    > individual messages
>    >    (which only contain one address/message)?
>    >      (the address list does not work in a nat environment.)
>    >      answer: both seems to be desired. 
>    > 
>    > => as I don't like the idea to mix MOBIKE and NAT-T I am in 
>    > favor of one message which can be submitted to the 
>    > authorization procedure once and gives less exchanges. Of 
>    > course this doesn't make the one address/message impossible.
>    
>    having an address list in the ike message makes nat 
> handling impossible. 

i need to correct myself here: i shouldn't say impossible. i should say
'impossible without using an additional protocol which allows to learn the
public ip address+ possible port'

>    
> => now I see: you speak about the first message when I speak 
> about NAT prevention in the first message and address list in 
> the next exchange.
does this make a difference. 

> I've already explained this but I used NAT prevention for two 
> purposes:
>  - make the choice between either NAT traversal and MOBIKE clear
>  - inject the peer addresses from the header into a protected 
> space

that's fine. it is certainly good to have an indication in the first message
exchange to tell the other peer whether to enable/disable nat handling
support. 

the second issue is fine with me. 

 BTW the first point is Pasi's idea, and it has the 
> extra advantage to be outside of the NAT traversal IPR.
very good. 


to come back to the original issue: 
if you have don't send a nat prevention payload (notification or vendor id)
in the first few messages and
if you have a nat somewhere along the path (at least between some src/dst
address pairs) then
you cannot send an address list (expect if you use another protocol which
allows you to learn your public ip address + port).

> 
> Thanks

ciao
hannes

> 
> [email protected]
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.