Re: Issue 41: Mandate NAT prevention if not doing NAT-T?

Francis Dupont <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   I think we can close this one.

=> but please explain what will be done for the security problem
itself (i.e., don't leave an undocumented security hole).

   This seems to be supported by Mohan and Francis (and myself),
   so with the small number of folks

=> I'll be fair: I won't use this against you (:-).

   that have participated this discussion, its propbably as close to
   consensus as we are going to get.
   
=> the only consensus we have is a MUST is too strong for IPv4.

   So, I think we can make the document leave the
   middle ground away from v6 but allowing it in v4.

=> this is a MAY for the opposite.

   ("NAT preventation SHOULD be enabled by default
   in IPv6 if NAT traversal is not enabled.", or words
   to that effect.)
   
=> this is far from enough! We need something for IPv4 and if it is
a MAY for the opposite a good security guideline.
BTW I agree with the proposed text, my concern is it is incomplete.

Regards

[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.