Jari Arkko wrote:
>
> This is a related issue, but partly different too. I agree that
> empty informational exchanges are not sufficient for an RR
> test, and a nonce is needed. Basically, an empty informational
> exchange just proves that the answer came from the peer, but
> not that it came from the address we wanted to test. I guess
> you could amend my list above as follows;
>
> - None, no tests.
>
> - A party willing to answer is on the path to the claimed
> address. This is the basic form of return routability
> test.
>
> - There is an answer from the tested address, and that
> answer was authenticated (including the address) to be
> from our peer.
>
> - There was an authenticated answer from the peer, but
> it is not guaranteed to be from the tested address
> or path to it (because the peer can construct a
> response without seeing the request).
>
> The last option corresponds to making an empty informational
> exchange. I think the first and the last options are not
> practical options; its either the second or the third
> option that we should adopt.
I my opinion, "Return routability" usually means the second one:
we verify that we have a route back to the party who made the
request. This is also what normal IKEv2 provides (either
statelessly using COOKIE payload, or with state and Ni/Nr).
Best regards,
Pasi
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.