[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: NAT64 and IPsec support




just to make sure that i understand this
During the last meeting, people suggested that NAT64 should provide the same level of IPSec support then regular v4NATs That make sense to me, since in general, we can think that a v4 NAT would be as incompatible with IPSec as NAT64
AFAIU, regular NAT support for IPSec is defined in rfc3948
However, in RFC3948, there is support for IPSec in NATs both in transport mode and tunnel mode. Tunnel mode seems differnet in the NATv4 case and the NAT64 case, so i understnad that it cannot work However, do you think that the transport mode IPSec as described in rfc3948 cannot work in NAT64?

=> Only ESP and only if IKE can negotiate it properly using the v4 addresses.

Hesham