>>But it has serious advantages over NAT-PT. >>It scales much better and does not break DNSsec. > i do not really think it a major advantage. > if you can use "AD is secure" proposal and let NAT-PT box to validate > DNSsec signature, we can get the same effect with NAT-PT. s/NAT-PT box/DNS ALG/ itojun