Re: does mobike support end-to-end use of tunnel mode?

Jari Arkko <[email protected]> Tue, 31 Jan 2006 10:57:39 +0200
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Mohan Parthasarathy wrote:

>In the Introduction,
>
>   The main scenario for MOBIKE is enabling a remote
>access VPN
>   user to move from one address to another without   
>
>   re-establishing all security associations with the 
>   VPN gateway.
>
>And in scope and limitations,
>
>   This document focuses on the main scenario outlined
>above, and
>   supports only tunnel mode IPsec SAs.
>
>This tells me that only VPN gateway is supported.
>  
>
I think so too, but maybe it should be made more
explicit, if people are misunderstanding it?

>In the host-to-host tunnel mode case, one can still
>assume that
>no two nodes (among a set of nodes) have the same
>"inner"
>address. Is there any problem in making such
>assumptions ?
>  
>
I was thinking about that, but I'm not sure I have a foolproof
method. Maybe FCFS allocation of inner addresses is one
approach, but it still has some question marks. For instance,
how do we know that we can deallocate an allocated address?

--Jari