Re: FW: external mobike-protocol-02 review (technical) (issue 42)
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote: > When the initiator is behind a NAT, it SHOULD include these > payloads in DPD messages, and compare the received ... > > When MOBIKE is in use, the host not behind a NAT SHOULD NOT > use the dynamic updates specified ... > > ==> How does the MOBIKE code know whether you're behind a NAT? > Is this done automatically as part of IKEv2 NAT detection? > Note that the spec doesn't seem to require running NAT presence > detection so with current spec this can't be done. Yes, this is done by IKEv2 NAT Traversal already (so saying that it must be done would be redundant). => you don't answer to the question: it is not required to run NAT presence detection. The simplest solution might be just to place the IP addresses in this payload (and mandate comparing them with the IP header)... Any comments from other on this? => so I am not the one which cares about peer address protection (:-). Regards [email protected]