Re: Issue 60: Addresses in IKE_SA_INIT/AUTH
Tero Kivinen <[email protected]> Wed, 16 Nov 2005 13:56:59 +0200
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
[email protected] writes: > Here's proposed text for issue 60. > > Rephrase Section 3.3 (Initial Tunnel Header Addresses > > [...] The addresses in the IKE_SA are initialized from the IP > header of the first IKE_AUTH request. > > The addresses are taken from the IKE_AUTH request because IKEv2 > requires changing from port 500 to 4500 if a NAT is discovered. > [...] > > And in Section 3.9 (NAT Prohibition): > > [...] all messages that can update the addresses associated with > the IKE_SA and/or IPsec SAs (the first IKE_AUTH request and all > INFORMATIONAL requests that contain any of the following > notifications: UPDATE_SA_ADDRESSES, ADDITIONAL_IP4/6_ADDRESS, > NO_ADDITIONAL_ADDRESSES) MUST also include a NO_NATS_ALLOWED > notification. [...] If they do not match, a response containing > an UNEXPECTED_NAT_DETECTED notification is sent. [...] > > If the exchange initiator receives an UNEXPECTED_NAT_DETECTED > notification in response to its INFORMATIONAL request, it SHOULD > retry the operation several times using new INFORMATIONAL requests. > Similarly, if the initiator receives UNEXPECTED_NAT_DETECTED in > the IKE_AUTH exchange, it SHOULD retry IKE_SA establishment > several times, starting from a new IKE_SA_INIT request. [...] > > Does this look OK? Looks ok for me. -- [email protected]