Re: WG last call for draft-ietf-l2tpext-failover-05.txt

Carlos Pignataro <[email protected]>
Newsgroups gmane.ietf.l2tpext
Organization cisco Systems, Inc.
Message-ID <[email protected]>
Vipin,

Yes, that clarification would help. Thanks.
Additionally, as we discussed in a brief private exchange, the recovery
tunnel MUST be terminated also if the Failed endpoint had not indicated
it was failover capable:

- Failed or non failed endpoint did not indicate it was failover capable.

Although a failed endpoint that is not failover capable would not
initiate the recovery tunnel to begin with, I was more concerned with 1.
impersonators and 2. provide clarity for implementors.

Thanks again,

--Carlos.

Circa 9/5/2005 8:52 AM, Vipin Jain said the following:
> Carlos,
> 
> The 'MUST terminate' in the section 2.2.1 you referred to is therefore recovery
> tunnel. I think we should clarify this. I will update the section with the
> same.
> 
> thanks,
> -- vipin
> 
> 
> --- Carlos Pignataro <[email protected]> wrote:
> 
> 
>>
>>Circa 9/2/2005 4:31 AM, Vipin Jain said the following:
>>
>>>Carlos,
>>>
>>>I'll skip the comments we agree upon. One quick comment below:
>>>
>>>
>>>
>>>>This is the scenario I meant: LCCE receives an SCCRQ containing the
>>>>Tunnel Recovery AVP. That means that the remote LCCE is establishing a
>>>>recovery tunnel. The Recover Tunnel Id and Recover Remote Tunnel Id in
>>>>the AVP identify an old tunnel for which the remote LCCE had not
>>>>previously included Failover Capability AVP upon establishment.
>>>>Shouldn't the recovery tunnel be torn down in that case?
>>>
>>>Upon receiving SCCRQ with Tunnel Recovery AVP in a recovery tunnel, an
>>
>>endpoint
>>
>>>should never tear down the old tunnel. Because unless the recovery tunnel
>>
>>is
>>
>>>fully established the authentication process isn't really complete.
>>
>>Therefore,
>>
>>>even if an endpoint didn't send Failover Capability AVP in the old tunnel,
>>
>>to
>>
>>>teardown the tunnel Recovery Tunnel must be established. Given that we must
>>>establish the recovery tunnel even if an endpoing doesn't support failover
>>
>>I'd
>>
>>>suggest an endpoing indicates that it supports failover and upon
>>
>>establishment
>>
>>>of recovery tunnel, it tears down the old tunnel.
>>
>>Vipin,
>>
>>I suspect part of the confusion may come from interpreting the following
>>text:
>><t>
>>It MUST terminate the tunnel if:
>>         - Non failed endpoint did not indicate it was failover capable.
>></t>
>>Where it says `MUST terminate the tunnel', is it referring to the old
>>tunnel or the recovery tunnel that must be terminated?
>>
>>Thanks,
>>
>>--Carlos.
>>
>>
>>>thanks,
>>>-- vipin
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>__________________________________________________
>>>Do You Yahoo!?
>>>Tired of spam?  Yahoo! Mail has the best spam protection around 
>>>http://mail.yahoo.com 
>>>
>>
>>-- 
>>--Carlos.
>>Escalation RTP - cisco Systems
>>
>>_______________________________________________
>>L2tpext mailing list
>>[email protected]
>>https://www1.ietf.org/mailman/listinfo/l2tpext
>>
> 
> 
> 
> __________________________________________________
> Do You Yahoo!?
> Tired of spam?  Yahoo! Mail has the best spam protection around 
> http://mail.yahoo.com 
> 

-- 
--Carlos.
Escalation RTP - cisco Systems
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.