RE: issue 34 proposal
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <13E3DA8B48E17D4C96D261A36A23FCD694E93C@xmb-rtp-208.amer.cisco.com> |
But, couldn't an attacker capture an ESP packet, change the src ip / port, and force us to start sending/flooding packets to an un-suspecting IP addr? At least a RR test would tell us that our 'peer' can indeed recv packets on the new IP. Still has MitM issues on the RR, mind you... Stephane. > -----Original Message----- > From: [email protected] > [mailto:[email protected]] > Sent: Tuesday, September 20, 2005 6:27 AM > To: Stephane Beaulieu [[email protected]] > Cc: [email protected]; Tero Kivinen; Jari Arkko; > [email protected] > Subject: Re: [Mobike] issue 34 proposal > > In your previous mail you wrote: > > If one does detect NAT change at ESP layer, what does one do? > > Do we do a return routability check on the new address > before updating > it's SADB? It would seem logical, but just want to make > sure we're on > the same page. > > => this is not logical at all! The SADB should be updated > ASAP and the RR check doesn't help at all: it only adds > delay, if the new address is bad the next packet with a good > address will fix the SADB. > > Regards > > [email protected] >