
|
3rd Party Bombing How much protection we offer against 3rd party bombing almost none, [A-B] (IKEv2 NAT-T) limited, [A-B and (B-C or A)] (return routability without cookies) partial [A-B and B-C] (return routability with cookies) Full [A inside path B-C] (authenticate outer IP-addresses, incompatible with NATs) Terms A, B = MOBIKE hosts, C = host attacked A-B = along path between A and B B-C = along path between B and C Do we care if A is the attacker |