Re: Issue 41: Mandate NAT prevention if not doing NAT-T?

Francis Dupont <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   I'd like to suggest the following
   text be added between paragraphs 2 and 3
   in Section 4.1:
   
     This attack can only be launched by on-path
     attackers that are capable of modifying either
     the initial IKE packets or other packets carrying
     NAT detection payloads (such as Dead Peer Detection
     messages). By modifying the outer addresses in
     these packets, the attackers can make the peers
     believe a new NAT or a changed NAT binding exists
     between them. The attack can continue as long as
     the attacker is on the path, modifying packets.

=> it should be clear that the packets are IKE messages.
In fact, we need the whole text to see if a confusion is possible,
and BTW the term "message" is better than "packet"...

     If this
     is no longer the case, IKEv2 and MOBIKE mechanisms
     designed to detect NAT mapping changes will eventually
     recognize that the intended traffic is not getting through,
     and update the addresses appropriately.
   
   Does this work for everyone?
   
=> this works.

Thanks

[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.