Re: Issue 41: Mandate NAT prevention if not doing NAT-T?

Francis Dupont <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   Normal IKEv2 also has this problem, and nobody so far has complained
   that IKEv2 would be too insecure (well, except you, perhaps).

=> the default policy is to check the addresses in the IP header
against identity and certificate payloads (cf the pki4ipsec I-D)
so the problem appears only in some scenarios where MOBIKE is
useful...

   IMHO we shouldn't waste time solving imaginary problems that are not
   problems in the real world...
   
=> if you need an exploit this can be done... If you need better
examples of imaginary problems where we've already wasted time
solving them I can give one.

   > => it seems you advocate for a SHOULD?
   
   No, I advocate for "NAT prevention SHOULD NOT be enabled by default",
   since it is much more likely to DoS yourself than prevent any attacks.
   
=> perhaps you consider that IPv6 is not (yet) the real world but
IPv6 folks do *not* want this "SHOULD NOT" at all. As there is no NAT
in IPv6 NAT prevention DoSes nobody and prevents an easy DoS attack.

And if you'd like to speak about the real world, I'd like to know
the proportion of implentations supporting NAT traversal by default
for IPv4. IMHO we likely get NAT detection for IPv4 and NAT prevention
for IPv6, solving the #41 in a way we can both agree about.

Regards

[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.