RE: issue 1: direct or indirect indicators
Tschofenig Hannes <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
hi francis, please see my comment below: > In your previous mail you wrote: > > > In your previous mail you wrote: > > > > a separate question but also of interest: > > - should a peer send an address list in one message or > > individual messages > > (which only contain one address/message)? > > (the address list does not work in a nat environment.) > > answer: both seems to be desired. > > > > => as I don't like the idea to mix MOBIKE and NAT-T I am in > > favor of one message which can be submitted to the > > authorization procedure once and gives less exchanges. Of > > course this doesn't make the one address/message impossible. > > having an address list in the ike message makes nat > handling impossible. i need to correct myself here: i shouldn't say impossible. i should say 'impossible without using an additional protocol which allows to learn the public ip address+ possible port' > > => now I see: you speak about the first message when I speak > about NAT prevention in the first message and address list in > the next exchange. does this make a difference. > I've already explained this but I used NAT prevention for two > purposes: > - make the choice between either NAT traversal and MOBIKE clear > - inject the peer addresses from the header into a protected > space that's fine. it is certainly good to have an indication in the first message exchange to tell the other peer whether to enable/disable nat handling support. the second issue is fine with me. BTW the first point is Pasi's idea, and it has the > extra advantage to be outside of the NAT traversal IPR. very good. to come back to the original issue: if you have don't send a nat prevention payload (notification or vendor id) in the first few messages and if you have a nat somewhere along the path (at least between some src/dst address pairs) then you cannot send an address list (expect if you use another protocol which allows you to learn your public ip address + port). > > Thanks ciao hannes > > [email protected] >