RE: Issue 41: Mandate NAT prevention if not doing NAT-T?

<[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Francis Dupont wrote:
   
> => you should explain why I'd like to eliminate this "middle
> ground": if none of the NAT_DETECTION_*_IP and NAT_PREVENTION is
> used, the addresses in the IP header are not protected because they
> are not "reflected" inside an IKE message. This opens the door at
> what I call the pseudo-transient NAT attack: an attacker in the path
> can patch headers in order to redirect the IPsec traffic to another
> node, usually in order to flood it. (it is pseudo-NAT because it
> acts like a NAT, it is transient because it has to be on the path
> only for some messages)

Normal IKEv2 also has this problem, and nobody so far has complained
that IKEv2 would be too insecure (well, except you, perhaps). IMHO 
we shouldn't waste time solving imaginary problems that are not
problems in the real world...

>    Or as I put in my IETF63 slides, this is a "trade-off 
>    between DoS-ing yourself and religious beliefs". In my opinion, 
>    we don't need to settle this trade-off in the protocol spec by 
>    saying "MUST use NAT prevention if not using NAT-T": the 
>    functionality is available for those who really want to use it 
>    (and understanding NAT_PREVENTION is mandatory for the responder).
>    
> => it seems you advocate for a SHOULD?

No, I advocate for "NAT prevention SHOULD NOT be enabled by default",
since it is much more likely to DoS yourself than prevent any attacks.

Best regards,
Pasi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.