Re: comments on draft-templin-isatap-issues

"Michael Cole"<[email protected]> Mon, 18 Nov 2002 23:26:28 -0800
Newsgroups gmane.ietf.ngtrans
Message-ID <[email protected]>

On Sun, 17 Nov 2002 23:12:54 +0200 (EET) Pekka Savola <[email protected]>
wrote:

> Two comments:
> 
> 4.6.  Operational Issue #6
> 
>    Sites that enable NATs internally may open
> themselves to operational
>    issues for ISATAP. The ISATAP IPv6/IPv4
> encapsulation will not tra-
>    verse standard NATs, and the only way to
> guarantee no NATs in the
>    path is through careful operational
> practices. A better long- term
>    solution may be to modify ISATAP to use
> UDP/IPv6/IPv4 encapsulation
>    as is currently done for Teredo [TEREDO].
> Such a modification would
>    draw ISATAP and Teredo even closer such that
> merging the two proto-
>    cols may procude the best possible
> transition mechanisms.
> 
> ==> I will change my attitude to ISATAP from
> "mildly positive" to "very 
> negative" if hacks like UDP tunneling or Teredo
> integration is done 
> (especially in the base spec).
> 
> We must not try to solve all the cases.  If
> enterprises have internal 
> NAT's, those could be different ISATAP domains,
> but let's not complicate 
> ISATAP any further than we have to.
> 
>    Similarly, ISATAP routers may employee a
> strategy for allowing/ dis-
> 
> ==> s/employee/employ/ (that typo is also
> copied to all of your other 
> recent drafts too :-)
> 
> -- 
> Pekka Savola                 "Tell me of
> difficulties surmounted,
> Netcore Oy                   not those you
> stumble over and fall"
> Systems. Networks. Security.  -- Robert Jordan:
> A Crown of Swords
> 
> 
> 

Actually, there are also two other possible complications:

1. Some of the better NAT boxes may also allow the use of TCP in addition to
UDP. The result is that ISATAP may not be able to tell the difference between
an IPv4 router and a NAT box.

2. ISATAP may not like timesharing a.k.a. terminal server systems if the
system has only ONE IPv4 address. You could even argue that the public
Internet cannot really tell the difference between a NAT box and a timesharing
system with only 1 global IPv4. That is, a NAT box causes a LAN to pretend
that it is a timesharing system.

Likewise, ISATAP would not be able to tell the difference between a
timesharing system with one local IPv4 address and an additional layer of
NATting, which could occur if an ISP is stuck with assigning RFC 1918
addresses to their customers. -- This is one example of why I have been
pushing for a Teredo address format that includes a field for device type so
that we have a way to deal with devices that engage in NAT-like behavior
(using the port number as an extension of the IPv4 address).

Mike Cole, [email protected]