Re: WG last call for draft-ietf-l2tpext-failover-05.txt
Carlos Pignataro <[email protected]>
| Newsgroups | gmane.ietf.l2tpext |
|---|---|
| Organization | cisco Systems, Inc. |
| Message-ID | <[email protected]> |
Vipin, Yes, that clarification would help. Thanks. Additionally, as we discussed in a brief private exchange, the recovery tunnel MUST be terminated also if the Failed endpoint had not indicated it was failover capable: - Failed or non failed endpoint did not indicate it was failover capable. Although a failed endpoint that is not failover capable would not initiate the recovery tunnel to begin with, I was more concerned with 1. impersonators and 2. provide clarity for implementors. Thanks again, --Carlos. Circa 9/5/2005 8:52 AM, Vipin Jain said the following: > Carlos, > > The 'MUST terminate' in the section 2.2.1 you referred to is therefore recovery > tunnel. I think we should clarify this. I will update the section with the > same. > > thanks, > -- vipin > > > --- Carlos Pignataro <[email protected]> wrote: > > >> >>Circa 9/2/2005 4:31 AM, Vipin Jain said the following: >> >>>Carlos, >>> >>>I'll skip the comments we agree upon. One quick comment below: >>> >>> >>> >>>>This is the scenario I meant: LCCE receives an SCCRQ containing the >>>>Tunnel Recovery AVP. That means that the remote LCCE is establishing a >>>>recovery tunnel. The Recover Tunnel Id and Recover Remote Tunnel Id in >>>>the AVP identify an old tunnel for which the remote LCCE had not >>>>previously included Failover Capability AVP upon establishment. >>>>Shouldn't the recovery tunnel be torn down in that case? >>> >>>Upon receiving SCCRQ with Tunnel Recovery AVP in a recovery tunnel, an >> >>endpoint >> >>>should never tear down the old tunnel. Because unless the recovery tunnel >> >>is >> >>>fully established the authentication process isn't really complete. >> >>Therefore, >> >>>even if an endpoint didn't send Failover Capability AVP in the old tunnel, >> >>to >> >>>teardown the tunnel Recovery Tunnel must be established. Given that we must >>>establish the recovery tunnel even if an endpoing doesn't support failover >> >>I'd >> >>>suggest an endpoing indicates that it supports failover and upon >> >>establishment >> >>>of recovery tunnel, it tears down the old tunnel. >> >>Vipin, >> >>I suspect part of the confusion may come from interpreting the following >>text: >><t> >>It MUST terminate the tunnel if: >> - Non failed endpoint did not indicate it was failover capable. >></t> >>Where it says `MUST terminate the tunnel', is it referring to the old >>tunnel or the recovery tunnel that must be terminated? >> >>Thanks, >> >>--Carlos. >> >> >>>thanks, >>>-- vipin >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>>__________________________________________________ >>>Do You Yahoo!? >>>Tired of spam? Yahoo! Mail has the best spam protection around >>>http://mail.yahoo.com >>> >> >>-- >>--Carlos. >>Escalation RTP - cisco Systems >> >>_______________________________________________ >>L2tpext mailing list >>[email protected] >>https://www1.ietf.org/mailman/listinfo/l2tpext >> > > > > __________________________________________________ > Do You Yahoo!? > Tired of spam? Yahoo! Mail has the best spam protection around > http://mail.yahoo.com > -- --Carlos. Escalation RTP - cisco Systems