Re: Issue 60: Addresses in IKE_SA_INIT/AUTH
Jari Arkko <[email protected]> Wed, 16 Nov 2005 14:42:11 +0200
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Ok for me too. --Jari Tero Kivinen wrote: >[email protected] writes: > > >>Here's proposed text for issue 60. >> >>Rephrase Section 3.3 (Initial Tunnel Header Addresses >> >> [...] The addresses in the IKE_SA are initialized from the IP >> header of the first IKE_AUTH request. >> >> The addresses are taken from the IKE_AUTH request because IKEv2 >> requires changing from port 500 to 4500 if a NAT is discovered. >> [...] >> >>And in Section 3.9 (NAT Prohibition): >> >> [...] all messages that can update the addresses associated with >> the IKE_SA and/or IPsec SAs (the first IKE_AUTH request and all >> INFORMATIONAL requests that contain any of the following >> notifications: UPDATE_SA_ADDRESSES, ADDITIONAL_IP4/6_ADDRESS, >> NO_ADDITIONAL_ADDRESSES) MUST also include a NO_NATS_ALLOWED >> notification. [...] If they do not match, a response containing >> an UNEXPECTED_NAT_DETECTED notification is sent. [...] >> >> If the exchange initiator receives an UNEXPECTED_NAT_DETECTED >> notification in response to its INFORMATIONAL request, it SHOULD >> retry the operation several times using new INFORMATIONAL requests. >> Similarly, if the initiator receives UNEXPECTED_NAT_DETECTED in >> the IKE_AUTH exchange, it SHOULD retry IKE_SA establishment >> several times, starting from a new IKE_SA_INIT request. [...] >> >>Does this look OK? >> >> > >Looks ok for me. > >