@herlesupreeth commented on this pull request.


In src/modules/ims_registrar_pcscf/service_routes.c:

>  			&& (ignore_contact_rxport_check
-					|| (c->received_port == _m->rcv.src_port)

My opinion is that in IMS the IPsec SA is negotiated for all transport protocols (so in practice UDP and TCP), hence if a UE managed to correctly encrypt whatever UDP/TCP packet correctly and send it to us on the correct Security-Association flows, we should allow it.

I agree


Reply to this email directly, view it on GitHub, or unsubscribe.
You are receiving this because you are subscribed to this thread.Message ID: <kamailio/kamailio/pull/3891/review/2138577712@github.com>