Re: issue 34 proposal

"Stephane Beaulieu (stephane)" <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <13E3DA8B48E17D4C96D261A36A23FCD69CF483@xmb-rtp-208.amer.cisco.com>
 


> 
> >Just to clarify...
> >
> >If one does detect NAT change at ESP layer, what does one do?
> >
> >Do we do a return routability check on the new address 
> before updating 
> >it's SADB?  It would seem logical, but just want to make 
> sure we're on 
> >the same page.
> >  
> >
> and Mohan wrote:
> 
> >Eventually, you want to recover faster too, right ? If it is 
> going to 
> >take a roundtrip extra compared to IKEv2 NAT-T before you 
> can use the 
> >address, how slower it is compared with the explicit update ?
> >  
> >
> I would note that the return routability text is already 
> being performed based on policy (as agreed upon in earlier 
> issues). So it isn't clear to me that we need to have an answer here.
> 

I think I missed this part of the discussion, but it seems like an
appropriate thing to do.  However, if a known attack is possible, we
might want to add this as a SHOULD or at least document it as a security
consideration.

Stephane.

> --Jari
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.