Re: Issue 41: Mandate NAT prevention if not doing NAT-T?
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote: Francis Dupont wrote: > In your previous mail you wrote: > > Are transient traffic redirection attacks serious enough to warrant it? > > => you miss the point: the attack is transient, not the traffic > redirection. In the MIPv4 context the traffic redirection is also transient. When the MN rebinds, the redirection ends. => no, it is only short. There is a huge difference between hacking some signaling messages and hacking the traffic flow. Now, if there is no equivalent mechanism in MOBIKE, the attack is more serious, but from previous mails it seems that this aspect is covered? => it is not covered but the situation is different for MOBIKE as explained in previous messages. BTW it seems the current protocol document requires in fact a NAT detection so now there are many reasons to drop the "middle ground", i.e., make NAT traversal or NAT prevention mandatory. Regards [email protected]