Re: Issue 41: Mandate NAT prevention if not doing NAT-T?

Sami Vaarala <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Moi,

Francis Dupont wrote:
> [...]
>    Since you seem to be the one person who thinks this is a 
> 
> => the one is this list...
> 
>    serious problem,
> 
> => the MIP WG considered it as serious too.

It's been some time but I believe the reaction in MIP WG was that
although the issue is real, it's not terribly serious.  Given the
location of the attacker (on the path), the attacker has many other
modes of attack than just transient traffic forwarding.

Because there's little that can be done in MIPv4 w.r.t. this problem,
namely just tweaking mobility binding lifetimes, it was documented
in RFC 3519 Security Considerations.  It's nice-to-know information
for an implementor.  Of course, having NAT prevention in a NAT traversal
document wasn't an option either :-).

Moreover, from my viewpoint, NAT prevention is something I don't
really understand. The real world is riddled with NATs, and it will
probably be the case with IPv6 too despite hope to the contrary.
So why make things more brittle?  Are transient traffic redirection
attacks serious enough to warrant it?

Best,

-Sami
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.