Summary

  • RFC 3519 let Mobile IPv4 data cross a NAT by using UDP and by making the outer source address and port observed by the home agent the effective care-of locator.
  • Mobile IP authentication protected the registration's internal care-of address, not the NAT-rewritten outer tuple. Short lifetimes, keepalives and IPsec limited consequences without authenticating that locator.

The problem began with a mismatch between two useful designs. Mobile IPv4 expected a home agent to tunnel traffic toward a globally meaningful care-of address. A NAPT expected TCP or UDP ports with which it could distinguish several private hosts sharing one public address. Plain IP-in-IP offered no such port pair, so data tunnelling could fail even while Mobile IP's UDP registration exchange passed.

RFC 3519 inserted the missing transport handle. A mobile node added a UDP Tunnel Request extension to its Registration Request. The home agent could answer with a UDP Tunnel Reply, choose IP-in-UDP, GRE-in-UDP or minimal encapsulation in UDP, and use port 434. Data and later registrations retained the same source port so the translator could preserve a usable mapping.

An affirmative reply meant something exact: the home agent assented to UDP tunnelling for that mobility binding. It did not mean the home agent had authenticated the translated address-and-port tuple, measured how long the NAT would keep it, or proved that the next inbound datagram would reach the mobile node.

To detect a NAT, the home agent compared the Registration Request's outer source address with the care-of address carried inside it. A mismatch suggested that the mobile node might reside behind a translator. If UDP tunnelling was permitted, the home agent ordinarily used the observed source as the effective care-of address.

That decision joined two evidence domains. The Mobile-Home or Foreign-Home Authentication Extension protected registration fields, including the care-of address in the message. The address and UDP port in the outer headers could be rewritten by the NAT. Those outer values were precisely what the home agent needed for return traffic, yet they were not covered by the authentication extension.

RFC 3519 did not hide the consequence. An attacker on the path could alter the IP and UDP headers of a Registration Request and redirect the resulting mobility binding. After changing the request, the attacker no longer needed to keep manipulating traffic. The home agent would continue using the false effective locator until the binding expired or the mobile node registered again.

The special foreign-agent path made the boundary even sharper. When a mobile node used a co-located care-of address but registered through a foreign agent, the Registration Request and the eventual tunnel could traverse different ports. The home agent therefore waited in a half-bound state for the mobile node's first keepalive before learning the tunnel port.

An observer of the registration exchange could race a bogus keepalive. RFC 3519 required the keepalive's outer source IP address to match the Registration Request, restricting an attacker to another port at that address. But the port still was not authenticated. Sending the legitimate first keepalive immediately reduced the race window; it did not turn the observed port into signed identity.

Keepalives served another purpose. A NAT could discard its mapping during an idle period. RFC 3519 used UDP-encapsulated ICMP Echo Request and Reply messages so the mobile node could detect a lost mapping. With no response after retransmissions, it could re-register, expose the new tuple to the home agent and shorten the interval for that network, never below ten seconds.

The default interval was 110 seconds, and a home agent could suggest another value. Yet the RFC prohibited the home agent from dynamically compensating for mapping loss because it lacked enough information to do so reliably. The mobile node, closer to the failure signal, owned the adaptation. This was an explicit localization of knowledge, not a universal NAT timer.

Three lifetimes could diverge. The authenticated mobility binding might still be valid. The NAT mapping might already have disappeared. A new outbound packet might create a new mapping while the home agent continued to send toward the old one. A binding receipt, mapping receipt and delivery receipt were therefore different objects.

The document recommended conservative, short binding lifetimes. Shortness limited how long a malicious redirect or undetected move could persist after intervention stopped. It did not prevent modification of outer headers. The mitigation reduced the time represented by bad state; it did not improve the authority of the input.

IPsec also retained a narrow role. RFC 3519 said it could protect user-data confidentiality if the intermediate network was untrusted, and the UDP method could carry IPsec-related traffic without changing IPsec associations during movement. It also said IPsec did not protect against the redirection attacks, apart from keeping hijacked user data confidential. Secrecy of content and authority over destination were separate.

The UNSAF discussion was unusually candid. The mechanism did not export the translated address to the mobile node, but the home agent still relied on an unprotected effective care-of address. A stronger design would discover the translations along the path, validate each translator's authority and carry the relevant NAT address inside the signed registration. RFC 3519 offered compatibility with existing NATs, not a claim that the trust gap had vanished.

IANA's Mobile IPv4 registry records the new message, request and reply extensions and error code. Those assignments let implementations agree on bits and values. They do not attest to one live mapping, one authenticated outer tuple or one successful tunnel.

RFC 3519's durable lesson is not that authentication failed. It is that an authenticated object can be combined with unauthenticated routing evidence to produce a consequential state. The registration could be valid while the effective care-of locator was false. Good operations must preserve both statements at once.

Sources