comments on draft-nikander-esp-beet
Jari Arkko <[email protected]> Tue, 21 Mar 2006 13:40:58 -0600
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
I have read the draft. Overall, its well written and specified. I do
have a number of comments, however:
o The fact that you are not doing full tunnel mode semantics limits
the application of this mode. For instance, in typical VPN setup
we do need the full semantics but would still perhaps appreciate
compressed headers.
Is there a solution that would allow this? I understand the
role of the BEET in the HIP context and how the inner identifiers
work, and the architecture. But is tehre something that
prevents a more general solution that would be better in
line with the general IPsec user community, including MOBIKE?
o Without the generalization to full tunnel mode, I think BEET
is something that can only be with MOBIKE when you use
either direct connections to the specific peers that you want
to talk to. This is something that is potentially useful, but
not as useful as the general solution would be. The limited
solution would though become more useful if we assume a
future where BTNS exists and can be used in connection with
MOBIKE and BEET.
Question: does BEET prevent usage in a situation where
a VPN gateway is used but the IPsec SAs are specific to
the peers that the client communicates with? I.e., not end
to end usage but inner addresses are fixed per SA pair.
o I remained unconvinced that the Mobile IP section is matches
what people would like to do (or even that its correct). I can
talk about the details off line, but my point is that the integrated
use of BEET in application X would require further work, and
might not be something that you want to commit to.
o If this work comes to MOBIKE, I'd rather not see the PF_KEY
part in the document.
--Jari