Re: does mobike support end-to-end use of tunnel mode?

Joe Touch <[email protected]> Thu, 02 Feb 2006 11:46:03 -0800
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



Erik Nordmark wrote:
> [email protected] wrote:
> 
> 
>>Well... if you have host-to-host tunnel mode IPsec working in a 
>>secure manner, MOBIKE could work as well. But this situation 
>>is pretty rare.
> 
> 
> Clarifying question: for this case are you assuming that the inner and 
> outer IP addresses for the tunnel must be different?
> 
> I think tunnel mode can be used (per the RFCs even if implementations 
> might not handle it) where the inner and outer IP addresses are the same.

In that case, it doesn't seem like the inner packet shouldn't be accepted.

The outer packet would be accepted because it is matches an IPsec rule
and is properly signed.

The inner packet, after decapsulation, should match the same rule, at
which point it should look like an unsigned packet, which should be
discarded.

Joe
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFD4mF7E5f5cImnZrsRAjgDAJkBcovuSxDjxHHop2MXF9N7q5v5kACgzgdV
nJZ7Z42+RsdV4ThwOYvhKTU=
=GIft
-----END PGP SIGNATURE-----