Re: Issue 41: Mandate NAT prevention if not doing NAT-T?
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote:
I'd like to suggest the following
text be added between paragraphs 2 and 3
in Section 4.1:
This attack can only be launched by on-path
attackers that are capable of modifying either
the initial IKE packets or other packets carrying
NAT detection payloads (such as Dead Peer Detection
messages). By modifying the outer addresses in
these packets, the attackers can make the peers
believe a new NAT or a changed NAT binding exists
between them. The attack can continue as long as
the attacker is on the path, modifying packets.
=> it should be clear that the packets are IKE messages.
In fact, we need the whole text to see if a confusion is possible,
and BTW the term "message" is better than "packet"...
If this
is no longer the case, IKEv2 and MOBIKE mechanisms
designed to detect NAT mapping changes will eventually
recognize that the intended traffic is not getting through,
and update the addresses appropriately.
Does this work for everyone?
=> this works.
Thanks
[email protected]