Francis Dupont wrote:
> In your previous mail you wrote:
>
> To me it looks like IKEv2 w/tunnel mode IPsec could work through
> "Basic-NAT-PT" type v4/v6 translation [RFC2766] (even if the
> implementations don't support IKEv2 NAT-T).
>
> (But I haven't gone through all the details.)
>
> => for instance how the NAT-PT translates the inner header (:-).
Well, it can't do that, of course -- but it's not necessarily needed,
because there's no need for the IP versions in inner and outer
headers to match.
Consider a case where we have a "remote access" VPN client connected
to, say, IPv6-only GPRS/UMTS network, and a corporate VPN gateway
connected to IPv4 Internet (and presumably some IPv4 "intranet" or
other protected network). If the IPv6 network has "Basic-NAT-PT"
deployed, the client could contact the gateway as usual (obtaining
a new IPv4 address from the protected network using configuration
payloads, etc.).
While I'm not very familiar with NAT-PT, to me it looks like this
would actually work just fine with normal IKEv2 (without NAT-T);
and the change you're proposing would forbid that (or force the
use of IKEv2 NAT-Traversal also for IPv6 :-)
(Well, that would be needed anyway once someone starts
deploying IPv6 NATs :-)
Best regards,
Pasi
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.