[2021-04-25 13:09:25+03:00]
Topics: [fun][ipsec]

IKEv2 про NAT

В RFC 7296 нравится введение про NAT раздел:

    Network Address Translation (NAT) gateways are a controversial
    subject.  This section briefly describes what they are and how they
    are likely to act on IKE traffic.  Many people believe that NATs are
    evil and that we should not design our protocols so as to make them
    work better.  IKEv2 does indeed specify some unintuitive processing
    rules so that NATs are more likely to work.

