Re: Issue: NAT-T interaction (#3)

Francis Dupont <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   So, you are saying that when you move behind NAT (the way you
  detect this is by sending address update with your address behind NAT,
  RR fails, the peer does not know how to reach you anymore, timeout and
  then detect NAT), negotiate a new SA (with NAT-T) ? Is that right ?

=> your scenario is wrong: when you move behind NAT your peer detect
this at the first IKE packet it receives from you and even knows how
to reach you. Then it will close the IKE SA and let you restart from
the beginning with hopefully NAT detection and NAT-T support.

   At some point in time, there was a discussion about adding NAT-D payloads
   in mobike itself.

=> MOBIKE needs something similar and more which can provide as a side
effect NAT detection. But NAT-D itself is not necessary in MOBIKE
and the IPsec WG decided to forbid direct no-NAT-T to NAT-T transition.

Regards

[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.