Re: Issue: NAT-T interaction (#3)
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote: So, you are saying that when you move behind NAT (the way you detect this is by sending address update with your address behind NAT, RR fails, the peer does not know how to reach you anymore, timeout and then detect NAT), negotiate a new SA (with NAT-T) ? Is that right ? => your scenario is wrong: when you move behind NAT your peer detect this at the first IKE packet it receives from you and even knows how to reach you. Then it will close the IKE SA and let you restart from the beginning with hopefully NAT detection and NAT-T support. At some point in time, there was a discussion about adding NAT-D payloads in mobike itself. => MOBIKE needs something similar and more which can provide as a side effect NAT detection. But NAT-D itself is not necessary in MOBIKE and the IPsec WG decided to forbid direct no-NAT-T to NAT-T transition. Regards [email protected]