Re: Issue 41: Mandate NAT prevention if not doing NAT-T?
Sami Vaarala <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Hi, Francis Dupont wrote: > return routability check that force the attacker to stay there > to continue the attack forever. > > => yes, mobile ip and mobike have different weapons. My concern is > they share the same issue but the WGs react in very different ways. A quick comment: if the attacker stays on the path, doing NAT forever (i.e. allows peers to exchange packets), then it's not really an attack. It's just plain NAT. At least in the MIPv4 context this becomes a relevant attack *only* if the attacker (a) intervenes in the binding establishment stage (acting as a NAT), and (b) then leaves the path. The result is either a defunct binding or a traffic flow redirected to a victim. If the attacker stays on and continues to perform the NAT function, traffic flow is not changed. Is there a difference in MOBIKE? I.e. is this an attack if the attacker stays on the path? Best, -Sami