Re: Issue 41: Mandate NAT prevention if not doing NAT-T?
Jari Arkko <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
First I wrote:
>So, I think we can make the document leave the
>middle ground away from v6 but allowing it in v4.
>("NAT preventation SHOULD be enabled by default
>in IPv6 if NAT traversal is not enabled.", or words
>to that effect.)
>
>
and then you Francis wrote:
>> BTW I agree with the proposed text, my concern is it is
>> incomplete.
>
>
and later Pasi writes:
>Since you seem to be the one person who thinks this is a
>serious problem, perhaps you could also provide some new
>text that better describes the situation?
>
and then you Francis wrote:
>IKE uses addresses it runs over, taken from IP headers, as
>endpoint addresses for IPsec SAs it establishes. If the
>addresses are left unprotected, an attacker can redirect the IPsec
>traffic to a third party just modifying the IP header of some IKE messages.
>Either NAT_DETECTION_*_IP or NO_NATS_ALLOWED detect the modification
>of the IP header on the path, including this attack.
>
>
Looking at this thread, it seems that there seems to be
support for our v6 text. We've since then been discussing
whether stronger language is needed for v4 as well. Right
now I don't see a lot of support for that. But let me ping a
couple of mobikers that I see in the same conference as I
am, to get their view.
The text that your provided above Francis looks like
material that could be included in the security
considerations section. Of course, we'd have to also
mention that under some conditions, the attack is
temporary. For instance, if the real node sends packets
after the attacker has left, the problem is corrected.
--Jari