Re: does mobike support end-to-end use of tunnel mode?

Mohan Parthasarathy <[email protected]> Tue, 31 Jan 2006 17:08:14 -0800 (PST)
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 > >In the Introduction,
> >
> >   The main scenario for MOBIKE is enabling a
> remote
> >access VPN
> >   user to move from one address to another without
>   
> >
> >   re-establishing all security associations with
> the 
> >   VPN gateway.
> >
> >And in scope and limitations,
> >
> >   This document focuses on the main scenario
> outlined
> >above, and
> >   supports only tunnel mode IPsec SAs.
> >
> >This tells me that only VPN gateway is supported.
> >  
> >
> I think so too, but maybe it should be made more
> explicit, if people are misunderstanding it?
> 
Sure. Extra clarification is always good.

> >In the host-to-host tunnel mode case, one can still
> >assume that
> >no two nodes (among a set of nodes) have the same
> >"inner"
> >address. Is there any problem in making such
> >assumptions ?
> >  
> >
> I was thinking about that, but I'm not sure I have a
> foolproof
> method. Maybe FCFS allocation of inner addresses is
> one
> approach, but it still has some question marks. For
> instance,
> how do we know that we can deallocate an allocated
> address?
> 
Just use static addresses. Perhaps, we should
understand
this use case a little better.

-mohan

> --Jari
> 
> _______________________________________________
> Mobike mailing list
> [email protected]
> https://www.machshav.com/mailman/listinfo.cgi/mobike
>