[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: suites vs. a la carte and IPcomp in IKEv2-05



 In your previous mail you wrote:

   UDP Encapsulation for NAT Traversal was negotiated in IKEv1 but is not in
   IKEv2. UDP Encapsulation is unilaterally selected by the initiator in IKEv2
   upon detecting a NAT, and any SA negotiated via an encapsulated IKE SA will
   also be encapsulated using the same UDP ports.
   
=> the IKEv2 mechanism has to be revised because it is subject to
a bidding down attack. Can we open a thread about this?

Thanks

Francis.Dupont@enst-bretagne.fr