Tero Kivinen wrote:
>
> My proposal would be to keep NAT-T and MOBIKE separate and you
> use one of them at time. If you are moved inside the NAT, and
> your policy allows NAT-T, then you move from MOBIKE to NAT-T.
> There is no need to send any address update notifications etc,
> as the NAT-T have built-in automatic IP-address change.
Here's another way to look at this issue: an implementation
that supports NAT-T has some additional information in
outbound security associations (conceptually speaking; an
implementation could store this information in some other
way as well):
- UDP encapsulation on/off flag
- keepalive sending on/off flag
- "automatically update peer address and port" on/off flag
- peer port
Normally these are set when the SA is created, and never updated
after that (except the port).
IMHO it does not make much sense to say that NAT-T and MOBIKE
should be kept separate, or that you move from MOBIKE to NAT-T.
The question should be whether something MOBIKE does can cause
this data to be changed after the SA was created, and I think the
answer should be "yes" (taking into account e.g. possible
restrictions of local policy)
Best regards,
Pasi
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.