Re: Issue: NAT-T interaction (#3)

Francis Dupont <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   Rather than testing NAT existance after each address change

=> in fact in IKEv2 NAT existence is checked only in the initial
exchange and can be forced by putting junked NAT-D stuff.

   I would recommend us consider forcing UDP wrapper on for all mobile
   cases.

=> IMHO this is not a stupid option when there is likely a NAT on the path.
But as a counterpart one should have a switch to disable NAT-T.

   Of course the drawback is that we add extra 8 bytes to the data.
   
=> NAT-T is also less secure (as Tero explained...)

Regards

[email protected]

PS: one extra issue is the support of NAT-T when both peers are
behind a NAT. IMHO there is nothing in the protocol against this.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.