Re: Issue 60: Addresses in IKE_SA_INIT/AUTH

Tero Kivinen <[email protected]> Wed, 16 Nov 2005 13:56:59 +0200
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
[email protected] writes:
> Here's proposed text for issue 60.
> 
> Rephrase Section 3.3 (Initial Tunnel Header Addresses 
> 
>    [...] The addresses in the IKE_SA are initialized from the IP 
>    header of the first IKE_AUTH request.
> 
>    The addresses are taken from the IKE_AUTH request because IKEv2
>    requires changing from port 500 to 4500 if a NAT is discovered. 
>    [...]
> 
> And in Section 3.9 (NAT Prohibition):
> 
>    [...] all messages that can update the addresses associated with
>    the IKE_SA and/or IPsec SAs (the first IKE_AUTH request and all
>    INFORMATIONAL requests that contain any of the following
>    notifications: UPDATE_SA_ADDRESSES, ADDITIONAL_IP4/6_ADDRESS,
>    NO_ADDITIONAL_ADDRESSES) MUST also include a NO_NATS_ALLOWED
>    notification.  [...] If they do not match, a response containing
>    an UNEXPECTED_NAT_DETECTED notification is sent. [...]
> 
>    If the exchange initiator receives an UNEXPECTED_NAT_DETECTED
>    notification in response to its INFORMATIONAL request, it SHOULD
>    retry the operation several times using new INFORMATIONAL requests.
>    Similarly, if the initiator receives UNEXPECTED_NAT_DETECTED in 
>    the IKE_AUTH exchange, it SHOULD retry IKE_SA establishment 
>    several times, starting from a new IKE_SA_INIT request.  [...]
> 
> Does this look OK?

Looks ok for me. 
-- 
[email protected]