RE: Issue: NAT-T interaction (#3)
"Jing Xiang" <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <6204FDDE129D364D8040A98BCCB290EF0E7D4F1A@zbl6c004.corpeast.baynetworks.com> |
I agree with Pasi's summary here. I think MOBIKE will definitely cause those NAT related SA info to change. Even if we use Address Update as NAT detection, we will probably still have to use the Address Update Ack to signal whether to turn UDP encap on or off, right? /Jing -----Original Message----- From: [email protected] [mailto:[email protected]] Sent: Wednesday, June 23, 2004 7:02 AM To: [email protected]; [email protected] Subject: RE: [Mobike] Issue: NAT-T interaction (#3) Tero Kivinen wrote: > > My proposal would be to keep NAT-T and MOBIKE separate and you > use one of them at time. If you are moved inside the NAT, and > your policy allows NAT-T, then you move from MOBIKE to NAT-T. > There is no need to send any address update notifications etc, > as the NAT-T have built-in automatic IP-address change. Here's another way to look at this issue: an implementation that supports NAT-T has some additional information in outbound security associations (conceptually speaking; an implementation could store this information in some other way as well): - UDP encapsulation on/off flag - keepalive sending on/off flag - "automatically update peer address and port" on/off flag - peer port Normally these are set when the SA is created, and never updated after that (except the port). IMHO it does not make much sense to say that NAT-T and MOBIKE should be kept separate, or that you move from MOBIKE to NAT-T. The question should be whether something MOBIKE does can cause this data to be changed after the SA was created, and I think the answer should be "yes" (taking into account e.g. possible restrictions of local policy) Best regards, Pasi _______________________________________________ Mobike mailing list [email protected] https://www.machshav.com/mailman/listinfo.cgi/mobike _______________________________________________ Mobike mailing list [email protected] https://www.machshav.com/mailman/listinfo.cgi/mobike