Re: Issue: NAT-T interaction (#3)
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote: Rather than testing NAT existance after each address change => in fact in IKEv2 NAT existence is checked only in the initial exchange and can be forced by putting junked NAT-D stuff. I would recommend us consider forcing UDP wrapper on for all mobile cases. => IMHO this is not a stupid option when there is likely a NAT on the path. But as a counterpart one should have a switch to disable NAT-T. Of course the drawback is that we add extra 8 bytes to the data. => NAT-T is also less secure (as Tero explained...) Regards [email protected] PS: one extra issue is the support of NAT-T when both peers are behind a NAT. IMHO there is nothing in the protocol against this.