Re: issue 34 proposal
"Stephane Beaulieu (stephane)" <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <13E3DA8B48E17D4C96D261A36A23FCD69CF483@xmb-rtp-208.amer.cisco.com> |
> > >Just to clarify... > > > >If one does detect NAT change at ESP layer, what does one do? > > > >Do we do a return routability check on the new address > before updating > >it's SADB? It would seem logical, but just want to make > sure we're on > >the same page. > > > > > and Mohan wrote: > > >Eventually, you want to recover faster too, right ? If it is > going to > >take a roundtrip extra compared to IKEv2 NAT-T before you > can use the > >address, how slower it is compared with the explicit update ? > > > > > I would note that the return routability text is already > being performed based on policy (as agreed upon in earlier > issues). So it isn't clear to me that we need to have an answer here. > I think I missed this part of the discussion, but it seems like an appropriate thing to do. However, if a known attack is possible, we might want to add this as a SHOULD or at least document it as a security consideration. Stephane. > --Jari >