Re: does mobike support end-to-end use of tunnel mode?

Mohan Parthasarathy <[email protected]> Thu, 26 Jan 2006 17:20:43 -0800 (PST)
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Jari,

This is the same case what Thomas Aura raised and the
Appendix has the answers. Regarding, host-to-host
tunnel mode, i would say that it is not supported by
observing the following.

In the Introduction,

   The main scenario for MOBIKE is enabling a remote
access VPN
   user to move from one address to another without   

   re-establishing all security associations with the 
   VPN gateway.

And in scope and limitations,

   This document focuses on the main scenario outlined
above, and
   supports only tunnel mode IPsec SAs.

This tells me that only VPN gateway is supported.

In the host-to-host tunnel mode case, one can still
assume that
no two nodes (among a set of nodes) have the same
"inner"
address. Is there any problem in making such
assumptions ?

-mohan


--- Jari Arkko <[email protected]> wrote:

> 
> Hi,
> 
> Erik read our protocol spec recently, and he had
> questions about the use of addresses in the
> protocol.
> Specifically, he was worried about "time shifting"
> or "address stealing" attacks where a host uses
> first address A in one place and then later B in
> another place. The question is what happens when
> some other host that comes later to the first place
> and gets the same address A as the first host. Will
> two hosts be able to communicate with the same peer?
> What will happen with ongoing sessions of the first
> host?
> 
> I explained that in MOBIKE the outer addresses
> as such don't matter; they are just the tunnel
> endpoints (although Appendix A describes a
> case where an implementation can get this
> wrong). What matters is the inner addresses --
> its those addresses that are used to match what
> packets go to what peer. Getting the address
> allocations right is essentially for the security
> of the system. This is indeed the case even without
> MOBIKE in base IKEv2 VPN usage*.
> 
> However, Erik asked whether the document makes
> it clear that it only supports the scenario where
> at least one of the peers is a gateway that ensures
> the address allocations are correct. And I was
> unable
> to answer that. Are we making it clear enough? Also,
> is it possible to use MOBIKE in host-to-host tunnel
> mode? If so, how? And have the security
> considerations
> relating to such usage been described?
> 
> Thoughts, anyone? Erik, feel free to post more
> detailed
> questions and concerns...
> 
> --Jari
> 
> *) But I was unable to find a statement either in
> RFC 4306 or the clarifications document about
> address allocation authorization issues.
> 
> _______________________________________________
> Mobike mailing list
> [email protected]
> https://www.machshav.com/mailman/listinfo.cgi/mobike
>