Re: Issue 60: Addresses in IKE_SA_INIT/AUTH

<[email protected]> Wed, 16 Nov 2005 10:33:41 +0200
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Here's proposed text for issue 60.

Rephrase Section 3.3 (Initial Tunnel Header Addresses 

   [...] The addresses in the IKE_SA are initialized from the IP 
   header of the first IKE_AUTH request.

   The addresses are taken from the IKE_AUTH request because IKEv2
   requires changing from port 500 to 4500 if a NAT is discovered. 
   [...]

And in Section 3.9 (NAT Prohibition):

   [...] all messages that can update the addresses associated with
   the IKE_SA and/or IPsec SAs (the first IKE_AUTH request and all
   INFORMATIONAL requests that contain any of the following
   notifications: UPDATE_SA_ADDRESSES, ADDITIONAL_IP4/6_ADDRESS,
   NO_ADDITIONAL_ADDRESSES) MUST also include a NO_NATS_ALLOWED
   notification.  [...] If they do not match, a response containing
   an UNEXPECTED_NAT_DETECTED notification is sent. [...]

   If the exchange initiator receives an UNEXPECTED_NAT_DETECTED
   notification in response to its INFORMATIONAL request, it SHOULD
   retry the operation several times using new INFORMATIONAL requests.
   Similarly, if the initiator receives UNEXPECTED_NAT_DETECTED in 
   the IKE_AUTH exchange, it SHOULD retry IKE_SA establishment 
   several times, starting from a new IKE_SA_INIT request.  [...]

Does this look OK?

Best regards,
Pasi