comments on draft-templin-isatap-issues
Pekka Savola <[email protected]> Sun, 17 Nov 2002 23:12:54 +0200 (EET)
| Newsgroups | gmane.ietf.ngtrans |
|---|---|
| Message-ID | <[email protected]> |
Two comments: 4.6. Operational Issue #6 Sites that enable NATs internally may open themselves to operational issues for ISATAP. The ISATAP IPv6/IPv4 encapsulation will not tra- verse standard NATs, and the only way to guarantee no NATs in the path is through careful operational practices. A better long- term solution may be to modify ISATAP to use UDP/IPv6/IPv4 encapsulation as is currently done for Teredo [TEREDO]. Such a modification would draw ISATAP and Teredo even closer such that merging the two proto- cols may procude the best possible transition mechanisms. ==> I will change my attitude to ISATAP from "mildly positive" to "very negative" if hacks like UDP tunneling or Teredo integration is done (especially in the base spec). We must not try to solve all the cases. If enterprises have internal NAT's, those could be different ISATAP domains, but let's not complicate ISATAP any further than we have to. Similarly, ISATAP routers may employee a strategy for allowing/ dis- ==> s/employee/employ/ (that typo is also copied to all of your other recent drafts too :-) -- Pekka Savola "Tell me of difficulties surmounted, Netcore Oy not those you stumble over and fall" Systems. Networks. Security. -- Robert Jordan: A Crown of Swords