RE: Issue: NAT-T interaction (#3)

<[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Tero Kivinen wrote:
>
> My proposal would be to keep NAT-T and MOBIKE separate and you
> use one of them at time. If you are moved inside the NAT, and
> your policy allows NAT-T, then you move from MOBIKE to NAT-T.
> There is no need to send any address update notifications etc,
> as the NAT-T have built-in automatic IP-address change.

Here's another way to look at this issue: an implementation 
that supports NAT-T has some additional information in 
outbound security associations (conceptually speaking; an
implementation could store this information in some other
way as well):

- UDP encapsulation on/off flag
- keepalive sending on/off flag
- "automatically update peer address and port" on/off flag
- peer port

Normally these are set when the SA is created, and never updated 
after that (except the port). 

IMHO it does not make much sense to say that NAT-T and MOBIKE 
should be kept separate, or that you move from MOBIKE to NAT-T.
The question should be whether something MOBIKE does can cause 
this data to be changed after the SA was created, and I think the
answer should be "yes" (taking into account e.g. possible 
restrictions of local policy)

Best regards,
Pasi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.