tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: SIP with NAT traversal and STUN using NPF



> The docs are probably presuming you not having a stateful firewall.

Stateful on-path devices break the assumptions underlying IP and the
protocols layered atop it.  NAT breaks them worse.

That as many things come as close as they do to working anyway is a
testament to their robustness.  I sometimes think it would have been
better if things had completely broken when faced with stateful paths;
it would have put a stop to this nonsense before it could get
established.

</curmudgeon>

/~\ The ASCII				  Mouse
\ / Ribbon Campaign
 X  Against HTML		mouse%rodents-montreal.org@localhost
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B


Home | Main Index | Thread Index | Old Index