Re: Issue 41: Mandate NAT prevention if not doing NAT-T?
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote: Normal IKEv2 also has this problem, and nobody so far has complained that IKEv2 would be too insecure (well, except you, perhaps). => the default policy is to check the addresses in the IP header against identity and certificate payloads (cf the pki4ipsec I-D) so the problem appears only in some scenarios where MOBIKE is useful... IMHO we shouldn't waste time solving imaginary problems that are not problems in the real world... => if you need an exploit this can be done... If you need better examples of imaginary problems where we've already wasted time solving them I can give one. > => it seems you advocate for a SHOULD? No, I advocate for "NAT prevention SHOULD NOT be enabled by default", since it is much more likely to DoS yourself than prevent any attacks. => perhaps you consider that IPv6 is not (yet) the real world but IPv6 folks do *not* want this "SHOULD NOT" at all. As there is no NAT in IPv6 NAT prevention DoSes nobody and prevents an easy DoS attack. And if you'd like to speak about the real world, I'd like to know the proportion of implentations supporting NAT traversal by default for IPv4. IMHO we likely get NAT detection for IPv4 and NAT prevention for IPv6, solving the #41 in a way we can both agree about. Regards [email protected]