Re: does mobike support end-to-end use of tunnel mode?
Mohan Parthasarathy <[email protected]> Thu, 26 Jan 2006 17:20:43 -0800 (PST)
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Jari, This is the same case what Thomas Aura raised and the Appendix has the answers. Regarding, host-to-host tunnel mode, i would say that it is not supported by observing the following. In the Introduction, The main scenario for MOBIKE is enabling a remote access VPN user to move from one address to another without re-establishing all security associations with the VPN gateway. And in scope and limitations, This document focuses on the main scenario outlined above, and supports only tunnel mode IPsec SAs. This tells me that only VPN gateway is supported. In the host-to-host tunnel mode case, one can still assume that no two nodes (among a set of nodes) have the same "inner" address. Is there any problem in making such assumptions ? -mohan --- Jari Arkko <[email protected]> wrote: > > Hi, > > Erik read our protocol spec recently, and he had > questions about the use of addresses in the > protocol. > Specifically, he was worried about "time shifting" > or "address stealing" attacks where a host uses > first address A in one place and then later B in > another place. The question is what happens when > some other host that comes later to the first place > and gets the same address A as the first host. Will > two hosts be able to communicate with the same peer? > What will happen with ongoing sessions of the first > host? > > I explained that in MOBIKE the outer addresses > as such don't matter; they are just the tunnel > endpoints (although Appendix A describes a > case where an implementation can get this > wrong). What matters is the inner addresses -- > its those addresses that are used to match what > packets go to what peer. Getting the address > allocations right is essentially for the security > of the system. This is indeed the case even without > MOBIKE in base IKEv2 VPN usage*. > > However, Erik asked whether the document makes > it clear that it only supports the scenario where > at least one of the peers is a gateway that ensures > the address allocations are correct. And I was > unable > to answer that. Are we making it clear enough? Also, > is it possible to use MOBIKE in host-to-host tunnel > mode? If so, how? And have the security > considerations > relating to such usage been described? > > Thoughts, anyone? Erik, feel free to post more > detailed > questions and concerns... > > --Jari > > *) But I was unable to find a statement either in > RFC 4306 or the clarifications document about > address allocation authorization issues. > > _______________________________________________ > Mobike mailing list > [email protected] > https://www.machshav.com/mailman/listinfo.cgi/mobike >