Re: Issue 60: Addresses in IKE_SA_INIT/AUTH

Jari Arkko <[email protected]> Wed, 16 Nov 2005 14:42:11 +0200
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Ok for me too. --Jari

Tero Kivinen wrote:

>[email protected] writes:
>  
>
>>Here's proposed text for issue 60.
>>
>>Rephrase Section 3.3 (Initial Tunnel Header Addresses 
>>
>>   [...] The addresses in the IKE_SA are initialized from the IP 
>>   header of the first IKE_AUTH request.
>>
>>   The addresses are taken from the IKE_AUTH request because IKEv2
>>   requires changing from port 500 to 4500 if a NAT is discovered. 
>>   [...]
>>
>>And in Section 3.9 (NAT Prohibition):
>>
>>   [...] all messages that can update the addresses associated with
>>   the IKE_SA and/or IPsec SAs (the first IKE_AUTH request and all
>>   INFORMATIONAL requests that contain any of the following
>>   notifications: UPDATE_SA_ADDRESSES, ADDITIONAL_IP4/6_ADDRESS,
>>   NO_ADDITIONAL_ADDRESSES) MUST also include a NO_NATS_ALLOWED
>>   notification.  [...] If they do not match, a response containing
>>   an UNEXPECTED_NAT_DETECTED notification is sent. [...]
>>
>>   If the exchange initiator receives an UNEXPECTED_NAT_DETECTED
>>   notification in response to its INFORMATIONAL request, it SHOULD
>>   retry the operation several times using new INFORMATIONAL requests.
>>   Similarly, if the initiator receives UNEXPECTED_NAT_DETECTED in 
>>   the IKE_AUTH exchange, it SHOULD retry IKE_SA establishment 
>>   several times, starting from a new IKE_SA_INIT request.  [...]
>>
>>Does this look OK?
>>    
>>
>
>Looks ok for me. 
>  
>