Re: Re: RR checks to avoid DoS attacks

Tero Kivinen <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Jari Arkko writes:
> Regarding simplicity, I'd like to avoid introducing too
> many additional parameters or configuration, so I'd
> rather have the MOBIKE RFC specify when the exchange
> needs to be done than make it configurable. Regarding
> security, the issue is amplification, some of which will
> still be possible during the timeout period for the RR test.
> We should also remember that the folks who need to decide
> whether to require a strict RR test before moving the flow
> are not the same ones as the potential victims.

What about the old stream, i.e. when do we cut out the stream from the
old address. I.e. If I am at address A, and send update for address B,
when do the gateway stop sending packets to my A address, and when
does it start sending them to B.

If I am still able to receive packets in address A, then I would like
to get my packets there until they are moved to address B (i.e. no
packets dropped there).

If I am not able to receive packets in address A, and I am moving to
address B, there will be packets dropped anyways, so I could simply
inform the gateway that it can stop sending my packets to address A
immediately, and continue sending them to B when the RR is finished.
-- 
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.