nsis-6----Page:9
1  2  3  4  5  6  7  8  9  10  11  12 

On the Security of Data Receiver behind a NAT
Data
Sender
NAT/
FW
Data
Receiver
Treat the signaling sessions (1) and (2) independently (authorization issue)
Do not update state established on the NAT/FW (created by the proxy mode signaling session) based on an e2e signaling session.
Proxy mode triggers a CREATE to deal with routing asymmetry and firewalls between the NAT/FW and the DR.

(1) End-to-End
Signaling
(2) Proxy Mode
Signaling
PPT Version