RE: Shipworm

"Christian Huitema" <[email protected]> Thu, 3 Oct 2002 08:02:17 -0700
Newsgroups gmane.ietf.ngtrans
Message-ID <F66A04C29AD9034A8205949AD0C9010403270BC8@win-msg-02.wingroup.windeploy.ntdev.microsoft.com>
1)       The official name is Teredo.

2)       The server does not make any distinction between the types of
clients. Relays and clients do.

3)       The "cone" bit indicates the type of restriction. It does not
matter how the restriction is implemented, i.e. in the NAT itself or in
a firewall adjunct.

4)       In the initial design, all relays sent packets from the same
address, i.e. from the "anycast" address reserved to the service; this
was a way to make all clients aware of the relay address. This approach
has been removed as it posed many operational problems.

5)       The current task of relays is very similar to resolving an ARP
request for a client; this is something that relays do easily.

 

-----Original Message-----
From: Michael Cole [mailto:[email protected]] 
Sent: Wednesday, October 02, 2002 7:56 PM
To: Christian Huitema
Cc: ngtrans
Subject: Shipworm

 

Dear Mr. Huitema,

 

Perhaps I should rephrase what I wrote the other day. I was probably a
little tired when I was reading something else. I was mistaking the
optimization for a plain cone NAT and a port restricted NAT.

 

1. Does the Shipworm Client and the Shipworm Server really need to
distinguish between a port restricted NAT (NAT+firewall in the same
program) and a plain cone NAT that is coupled to a firewall? It might
help to include this scenario in the definition of a port restricted NAT
- most port restrictions are deliberate anyways.

 

2. Could the optimization for a plain cone NAT be applied to a port
restricted NAT by somehow sending the address of the Teredo Relay to the
Teredo Client so that the client can tell the firewall to recognize
Relay's address? (Modified version of 4.1.4)

 

 

 

--- Michael Cole

--- [email protected]

--- EarthLink: It's your Internet.