Re: Issue 33: Changing ports 500/4500 and RR
Jari Arkko <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
[email protected] wrote: >Tero Kivinen wrote: > > > >>>2.7 NAT prevention >>> >>> >>... >> >> >>> If the IKE_SA_INIT request included NAT_DETECTION_*_IP >>> payloads but no NAT_PREVENTION payload, the situation is >>> different since the initiator may at this point change >>> from port 500 to 4500. In this case, the responder >>> initializes (local_address, local_port, peer_address, >>> peer_port) from the first IKE_AUTH request. It may also >>> decide to perform a return routability check soon after >>> the IKE_AUTH exchanges have been completed. >>> >>> > > > >>Why does it need to do the return routability check? IKEv2 >>NAT-T does not do return routability checks there, why should >>we do? Note, that the initiator will not see any IPsec packets >>thus he cannot for example start TCP sessions, as those are >>not retransmittede to secondary addresses. I cannot really see >>how he could mount any real attack at this phase. >> >> > >Hmm.. you're probably right, there's no good reason to do >the return routability check at this stage. I guess we can >delete the last sentence..? > > Agreed. --Jari