Re: Issue 41: Mandate NAT prevention if not doing NAT-T?
Jari Arkko <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
[email protected] wrote: >No, I advocate for "NAT prevention SHOULD NOT be enabled by default", >since it is much more likely to DoS yourself than prevent any attacks. > > This isn't necessarily the case. The most likely dos-yourself scenario is not enabling NAT traversal, because NATs exists in almost all public network access. Unless I'm mistaken, plain old ESP does not get through the most widely deployed NAT types. There's the small likelihood that you have some atypical NAT in between, and there NAT prevention makes a difference in the final outcome. But the typical case dominates, so we're essentially debating whether the failure in this configuration has a 95% or 96% probability of occurring... --Jari