Summary

  • RFC 5265 permits an internal classification only after the internal home agent accepts a registration through that particular interface, returns the Trusted Networks Configured extension, and the interface has not changed connection status.
  • The safe operational evidence is a renewable, interface-scoped verdict: bind the protected reply to the matched trusted-source rule, policy version, attachment, monitoring deadline and traffic-gate state.

A green reply arrived at the dangerous moment

The mobile node had just acquired connectivity. Its internal home agent answered a registration request, the answer carried the Trusted Networks Configured extension, and Mobile IPv4 authentication protected the exchange. The node could treat that interface as inside and avoid unnecessary VPN encapsulation.

That is the attractive reading. The dangerous reading adds one word: now. Operators turn a current result into “this device is on the trusted network” and carry the label across a radio handoff, a route change or another interface. RFC 5265 does not.

It says successful registration through interface X says nothing about interface Y. It also conditions the inside inference on the connection status not having changed since the exchange. The protocol therefore models trust as a result with coordinates, not a property of the machine.

TNC certifies a configured check, not a physical place

RFC 5265 depends first on an enterprise firewall that prevents an external network from reaching the internal home agent directly. It then adds a second control: the home agent holds an explicit list of trusted IP subnets, trusts none by default, silently drops registrations from outside them, and inserts TNC in replies to requests from trusted addresses.

The extension is meaningful. It tells the mobile node that the home agent performed the configured source-address check. Together with authentication and replay protection, the reply is evidence that the request reached the expected authority and satisfied that authority's rule.

But the rule is still configuration. TNC does not measure the building, authenticate the access point, inspect the cable or confer application privileges. If firewall reachability and the trusted-subnet list are wrong together, a correctly processed exchange can support the wrong conclusion. A protocol-valid verdict is not proof that every premise behind it was correct.

The interface is part of the fact

Per-interface tracking is not bookkeeping decoration. A laptop may have Ethernet, Wi-Fi and a cellular modem active at once. One path may reach the i-HA directly while another faces the public network. Collapsing their observations into one device-wide “trusted” bit would let evidence from the safe path authorize plaintext on the unsafe one.

For this reason, the minimum useful record is not merely the reply code. It includes the interface identity, point of attachment, source address, destination home agent, request and response identifiers, authentication and replay result, presence of TNC, the matched subnet rule and the time of acceptance. Without those bindings, a later reviewer cannot tell which path the result governed.

Movement revokes reuse before it disproves history

An interface can move from an internal network to an untrusted network in an instant. The earlier reply does not become fraudulent; it becomes inapplicable. RFC 5265 requires the node, on a detected connection-status change, to stop relaying user data immediately, classify the new attachment, and resume only after detection, registration and any necessary VPN establishment have completed.

This is a subtle but important incident distinction. “The old trust result was false” points investigators toward compromised authentication. “The old result was reused outside its scope” points toward missing change detection, shared state between interfaces, a traffic-gate failure or stale policy. Both can expose plaintext, but they demand different repairs.

A timer covers what layer two may miss

Not every change announces itself cleanly. Upstream routing can move while the link remains up; layer-two notification can arrive late or fail. RFC 5265 therefore requires periodic re-registration while inside, regardless of the binding lifetime.

The monitoring interval creates a hard evidence horizon. More than T_MONITOR seconds after the last successful i-HA registration, the node must not send or receive user packets. It must drop them or queue them, and a queue cannot drain until re-registration succeeds without an intervening connection change.

The timer does not eliminate exposure. The RFC expressly acknowledges that some leakage may be unavoidable. It gives administrators a way to bound the interval during which an undetected change could leave plaintext flowing. Shorter intervals reduce that window while increasing signalling and dependence on home-agent availability.

Silence is a safe failure, not a location claim

The proposed algorithm asks the internal and external home agents in parallel. A reply from the external home agent supports a tentative outside result while the node continues waiting for the internal one. An authenticated i-HA reply carrying TNC supports the inside result.

No reply proves much less. Loss, filtering, routing failure, congestion or an unavailable server can all look like silence. The defensible action is conservative—retain encryption, block traffic or continue detection—not to transform absence into evidence of physical location.

This is why the closed traffic gate matters as much as the classifier. A classification system can be imperfect and still fail safely if uncertain state cannot release ordinary traffic. A perfect log attached to a bypassable gate is weaker.

The secret can be the weakest control

Mobile IPv4 and IPsec do different jobs. In this design, Mobile IPv4 signalling determines mobility and, at the internal boundary, whether encryption may be dropped. IPsec continues to protect confidentiality, integrity and replay resistance between its endpoints even if routing is redirected.

RFC 5265 warns that a weak shared secret at the internal home agent is fatal to this decision: an attacker who can forge the relevant exchange may induce the mobile node to stop encrypting. The incident is not “IPsec cryptography failed.” It is “the control deciding whether IPsec was needed accepted counterfeit evidence.”

Likewise, a pseudo-NAT attack can redirect flows and cause resource consumption, outage or denial of service without breaking IPsec confidentiality. Reachability, path selection and cryptographic protection occupy different reality layers. A useful receipt keeps them separate.

What a trust-boundary receipt must preserve

For consequential use, retain:

  • device and exact interface identity, link state and point-of-attachment evidence;
  • request, response, timestamps, retransmissions, result code and TNC presence;
  • Mobile IPv4 security-association identity, authentication result and replay decision;
  • observed source address, matched trusted subnet and home-agent policy version;
  • firewall and routing policy versions relevant to direct i-HA reachability;
  • last successful validation time, T_MONITOR, grace period and next deadline;
  • every connection-status signal, missed signal and reclassification transition;
  • whether user traffic was blocked, dropped or queued during uncertainty;
  • VPN establishment and encryption state before traffic was released; and
  • downstream authorization decisions, recorded separately from network classification.

The receipt should state its scope in plain language: this interface satisfied this home agent's configured inside test at this time and remained within its freshness window. Anything broader is a new claim requiring new evidence.

Sources