RE: NAT Traversal

"Jayant Shukla" <jshukla@trlokom.com> Mon, 04 March 2002 07:25 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g247Pd807955; Sun, 3 Mar 2002 23:25:39 -0800 (PST)
Received: by lists.tislabs.com (8.9.1/8.9.1) id BAA20560 Mon, 4 Mar 2002 01:34:39 -0500 (EST)
From: Jayant Shukla <jshukla@trlokom.com>
To: "'Chinna N.R. Pellacuru'" <pcn@cisco.com>, 'Henrik Levkowetz' <henrik@ipunplugged.com>
Cc: 'ipsec mailling list' <ipsec@lists.tislabs.com>
Subject: RE: NAT Traversal
Date: Sun, 03 Mar 2002 22:42:57 -0800
Message-ID: <000101c1c347$d2511cb0$0100a8c0@trlhpc1>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
Importance: Normal
In-Reply-To: <Pine.GSO.4.33.0203030734130.28716-100000@cypher.cisco.com>
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk


> -----Original Message-----
> From: owner-ipsec@lists.tislabs.com
[mailto:owner-ipsec@lists.tislabs.com]
> On Behalf Of Chinna N.R. Pellacuru
> 
> For our solution we do not require to even discover NAT. The SPIs can
be
> generated as a pair in all cases because this is such a simple
operation.
> If there are any NATs enroute, they will use this property to
de-multiplex
> the IPsec traffic and do IPsec pass-through.
> 

So, you are suggesting modifications to IKE, right?

This is interesting! According to your earlier e-mail, IKE modification
for "NAT discovery" is not acceptable, but now IKE modification for "NAT
traversal" is acceptable?

Regards,
Jayant
http://www.trlokom.com 

> If doing encapsulation, you MUST do NAT discovery becuase the price
they
> pay for encapsulation is high, 16 bytes of overhead (okay not 24 as I
said
> in my previous mail). So, you want to do encapsulation and send
keepalives
> every 9 seconds, only when you are absolutely sure that it is needed.
> 
>     Thanks again for your support,
>     chinna