Re: RR checks to avoid DoS attacks

Tero Kivinen <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
[email protected] writes:
> Perhaps we could re-use the COOKIE Notify payload for this?
> That is, when the gateway receives a request to update the SAs,
> it could reply with a COOKIE payload and the client would
> re-send the request with the cookie? This way, RR could be also
> skipped if necessary (for instance when switching back to an
> address that was already tested recently).

I think that would be good solution. 

> Personally I think it would be also acceptable to do the RR 
> check after changing the address. That is, the gateway updates 
> the SAs immediately, but then sends a separate informational 
> exchange containing some kind of cookie. What do others think
> about this?

I would think that would be ok, for most of the scenarios. In some
cases (completely unauthenticated connection to video stream server)
could put the traffic on hold while waiting the RR to succeed, but
that would be local matter.
-- 
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.