ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
ikev2_natt.h File Reference

IKEv2 NAT traversal: NAT detection (RFC 7296 sec 2.23) and the UDP encapsulation demux (RFC 3948 sec 2). More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

IKEv2 NAT traversal: NAT detection (RFC 7296 sec 2.23) and the UDP encapsulation demux (RFC 3948 sec 2).

RFC 7296 sec 2.23: both peers put NAT_DETECTION_SOURCE_IP and NAT_DETECTION_DESTINATION_IP Notify payloads in their IKE_SA_INIT messages, just after Ni and Nr. The data of the first is a SHA-1 digest of the SPIs in the order they appear in the header, the IP address, and the port the packet was sent from; the data of the second is the same digest over the address and port it was sent to. The Notify Message Types are 16388 and 16389 (sec 3.10.1).

A recipient recomputes each digest over the addresses it actually observes. No match on any received NAT_DETECTION_SOURCE_IP means the peer's source was translated, so the peer is behind a NAT. A mismatching NAT_DETECTION_DESTINATION_IP means this system is behind a NAT and should send the keepalives of RFC 3948. Once a NAT is detected both peers move to port 4500 and encapsulate ESP in UDP.

RFC 3948 sec 2.2: an IKE message on port 4500 is prefixed with the Non-ESP Marker, four zero octets aligned with the SPI field of an ESP packet, and sec 2.1 requires that SPI to be non-zero, so the marker separates IKE from ESP. RFC 3948 sec 2.3: a NAT-keepalive is a one octet payload with the value 0xFF.

The module exports one symbol, IkeNatt. Everything in ikev2_natt.c has internal linkage.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file ikev2_natt.h.