[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

ISATAP and admin/IP domains [RE: 3gpp-analysis: Recommendation on tunneling in the UE]



On Tue, 18 Nov 2003, Karim El-Malki (HF/EAB) wrote:
> ISATAP tunneling in the UE is not for inter-IP-domain. There can be one
> or more L2 networks between the UE the ISATAP box but the UE and ISATAP
> box would always be in the same IP domain. Maybe this was a comment in
> reference to 3gpp roaming? If so I want to point out that it is L2
> roaming (not L3 roaming). So there is no crossing of IP domain.

I was talking about administrative domains, not IP domains. (Sorry for 
confusion.)

The 3GPP operator cannot trust the UE or the user.  They must be treated 
as "hostile".  This is very, very different from e.g. most enterprise 
networks where ISATAP was originally more or less envisioned for.

-- 
Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings