On May 7, 2008, at 2:22 PM, Francois Audet wrote: > > > For STUN-over SIP, I'm not too sure how it should work. (I don't > really care either > to be honest). I think the point of the outbound draft was to say > "don't send STUN > over SIP unless you know your server supports it (through outbound > registration, or > explicit configuration, or keep parameter). >
That's exactly the point. You're not likely to DOS yourself by sending double-crlf to a proxy. But you ARE likely to DOS yourself by sending STUN to the same port to which you send SIP. So the rule is "Don't STUN a proxy's SIP port unless you're sure it supports it". Outbound already provides a discovery mechanism letting a UA find out whether or not a proxy supports STUN over SIP. If I understand it correctly, this draft is an attempt to make such a mechanism available in the absence of Outbound. -- Dean _______________________________________________ Sip mailing list https://www.ietf.org/mailman/listinfo/sip This list is for NEW development of the core SIP Protocol Use [EMAIL PROTECTED] for questions on current sip Use [EMAIL PROTECTED] for new developments on the application of sip
