Re: Issue 33: Changing ports 500/4500 and RR

Jari Arkko <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
[email protected] wrote:

>Tero Kivinen wrote:
>
>  
>
>>>2.7  NAT prevention
>>>      
>>>
>>...
>>    
>>
>>>   If the IKE_SA_INIT request included NAT_DETECTION_*_IP
>>>   payloads but no NAT_PREVENTION payload, the situation is
>>>   different since the initiator may at this point change
>>>   from port 500 to 4500.  In this case, the responder
>>>   initializes (local_address, local_port, peer_address,
>>>   peer_port) from the first IKE_AUTH request.  It may also
>>>   decide to perform a return routability check soon after
>>>   the IKE_AUTH exchanges have been completed.
>>>      
>>>
>
>  
>
>>Why does it need to do the return routability check? IKEv2
>>NAT-T does not do return routability checks there, why should
>>we do? Note, that the initiator will not see any IPsec packets
>>thus he cannot for example start TCP sessions, as those are
>>not retransmittede to secondary addresses. I cannot really see
>>how he could mount any real attack at this phase.
>>    
>>
>
>Hmm.. you're probably right, there's no good reason to do
>the return routability check at this stage. I guess we can
>delete the last sentence..?
>  
>
Agreed. --Jari
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.