Re: Issue 60: Addresses in IKE_SA_INIT/AUTH
<[email protected]> Wed, 16 Nov 2005 10:33:41 +0200
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Here's proposed text for issue 60. Rephrase Section 3.3 (Initial Tunnel Header Addresses [...] The addresses in the IKE_SA are initialized from the IP header of the first IKE_AUTH request. The addresses are taken from the IKE_AUTH request because IKEv2 requires changing from port 500 to 4500 if a NAT is discovered. [...] And in Section 3.9 (NAT Prohibition): [...] all messages that can update the addresses associated with the IKE_SA and/or IPsec SAs (the first IKE_AUTH request and all INFORMATIONAL requests that contain any of the following notifications: UPDATE_SA_ADDRESSES, ADDITIONAL_IP4/6_ADDRESS, NO_ADDITIONAL_ADDRESSES) MUST also include a NO_NATS_ALLOWED notification. [...] If they do not match, a response containing an UNEXPECTED_NAT_DETECTED notification is sent. [...] If the exchange initiator receives an UNEXPECTED_NAT_DETECTED notification in response to its INFORMATIONAL request, it SHOULD retry the operation several times using new INFORMATIONAL requests. Similarly, if the initiator receives UNEXPECTED_NAT_DETECTED in the IKE_AUTH exchange, it SHOULD retry IKE_SA establishment several times, starting from a new IKE_SA_INIT request. [...] Does this look OK? Best regards, Pasi