Re: Issue 41: Mandate NAT prevention if not doing NAT-T?
Jari Arkko <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Francis Dupont wrote: > In your previous mail you wrote: > > The text that your provided above Francis looks like > material that could be included in the security > considerations section. Of course, we'd have to also > mention that under some conditions, the attack is > temporary. For instance, if the real node sends packets > after the attacker has left, the problem is corrected. > >=> unfortunately this is not true: the problem can be corrected >only with an explicit action (an address update to the right address). > > Right. The real node needs to do an address update. --Jari