Re: does mobike support end-to-end use of tunnel mode?
Mohan Parthasarathy <[email protected]> Tue, 31 Jan 2006 17:08:14 -0800 (PST)
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
> >In the Introduction, > > > > The main scenario for MOBIKE is enabling a > remote > >access VPN > > user to move from one address to another without > > > > > re-establishing all security associations with > the > > VPN gateway. > > > >And in scope and limitations, > > > > This document focuses on the main scenario > outlined > >above, and > > supports only tunnel mode IPsec SAs. > > > >This tells me that only VPN gateway is supported. > > > > > I think so too, but maybe it should be made more > explicit, if people are misunderstanding it? > Sure. Extra clarification is always good. > >In the host-to-host tunnel mode case, one can still > >assume that > >no two nodes (among a set of nodes) have the same > >"inner" > >address. Is there any problem in making such > >assumptions ? > > > > > I was thinking about that, but I'm not sure I have a > foolproof > method. Maybe FCFS allocation of inner addresses is > one > approach, but it still has some question marks. For > instance, > how do we know that we can deallocate an allocated > address? > Just use static addresses. Perhaps, we should understand this use case a little better. -mohan > --Jari > > _______________________________________________ > Mobike mailing list > [email protected] > https://www.machshav.com/mailman/listinfo.cgi/mobike >