RE: issue 3: nat traversal
Bill Sommerfeld <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <1103673053.7998.58.camel@thunk> |
On Mon, 2004-12-20 at 03:25, Tschofenig Hannes wrote: > my impression so far was that we cannot assume that there are some protocols > which allow to securely obtain a nat binding. if we manage it to update > existing nats to provide this type of protocol support then i would be very > happy. however, we would liket to have a protocol which can be deployed > today (even if there are some limitations). In the meantime, I wonder if we could get any leverage out of a "NAT expected" bit -- carried in a secured part of the protocol. This would need to be administratively configured. It would probably have to default to "on". If both peers have that bit cleared you would do NAT prevention; otherwise, you would do NAT traversal if a NAT is detected. - Bill