RE: issue 3: nat traversal
Paul Hoffman / VPNC <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <p06200712bdee81da1a80@[10.20.30.249]> |
At 8:37 PM -0500 12/21/04, Bill Sommerfeld wrote: >To clarify, "nat expected" false means "I don't expect *my* address >to be rewritten by a NAT". Ah! That's good, because it is certainly more predictable. >So an administrator who assigned systems globally unique globally routed ipv4 >addresses, who wanted to avoid nat-like attacks when talking to other systems >with globally unique globally routed addresses, could clear the "nat expected" >bit for those addresses on those systems. That makes it much easier to predict. --Paul Hoffman, Director --VPN Consortium