RE: issue 3: nat traversal

Bill Sommerfeld <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <1103679460.7998.152.camel@thunk>
On Tue, 2004-12-21 at 19:41, Paul Hoffman / VPNC wrote:
> At 6:50 PM -0500 12/21/04, Bill Sommerfeld wrote:
> >In the meantime, I wonder if we could get any leverage out of a "NAT expected"
> >bit -- carried in a secured part of the protocol.  This would need to be
> >administratively configured.  It would probably have to default to "on".
> 
> How would an administrator know how to set that bit? 

First off, it's only interesting to people who want to do (selective) nat prevention.

To clarify, "nat expected" false means "I don't expect *my* address to be rewritten by a NAT".

So an administrator who assigned systems globally unique globally routed ipv4
addresses, who wanted to avoid nat-like attacks when talking to other systems
with globally unique globally routed addresses, could clear the "nat expected"
bit for those addresses on those systems.

						- Bill
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.