MOBIKE and MIP6 (was RE: Preliminary minutes from the WG last week)
"Narayanan, Vidya" <[email protected]> Mon, 3 Apr 2006 21:00:09 -0700
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
All, Just catching up with this discussion - I do think that the MOBIKE-MIP6 interactions need more detail. I recap a gist of what I posted on the MIP6 list on this topic (for those of you on both lists, I apologize for the repeat): There are two cases with respect to MOBIKE and MIP6: 1. MOBIKE (or IKEv2) and MIP6 have different endpoints - i.e., MOBIKE between MN and VPN GW, MIP6 between MN and HA This is a valid model and has applicability in some markets (where data needs to be protected using IPsec in a VPN-over-MIP model). This would be a reason to write a draft similar to the MIP4-MOBIKE one. I'm not sure if there is a need to do the draft on this yet though (let the users of those markets ask for it?). 2. MOBIKE (or IKEv2) and MIP6 endpoints are the same - i.e., both run between the MN and HA In this model, the scope of the IKEv2 SA is important to decide whether MOBIKE or the 'K' bit in MIP6 is used to update the IP address of the SA. A few different cases to look at here: a. The IKEv2 SA is used to create IPsec SAs solely for MIP6 signaling protection b. The IKEv2 SA is used to create child SAs for applications other than MIP6 (e.g., SIP, data traffic protection, etc.) C. The IPsec SA created from the IKEv2 SA protects more than just MIP6 signaling (i.e., the same IPsec SA protects SIP, etc.) In the case of a, it might be acceptable to let the 'K' bit do the address update for IKEv2. For b and c, the fact that the IKEv2 and IPsec SAs have an applicability that is broader than MIP6 says that MIP6 should not be updating those SAs. I think we would be shortsighted to go the route of using MIP6 in place of MOBIKE there - meshing MIP6 and IKEv2 in those cases seems an architectural limitation waiting to be unraveled. Vidya > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of James Kempf > Sent: Monday, April 03, 2006 1:52 PM > To: Vijay Devarapalli; gabriel montenegro; Yaron Sheffer; Paul Hoffman > Cc: [email protected] > Subject: Re: [Mobike] Preliminary minutes from the WG last week > > OK, Vijay, I get the point. You don't think there is an > issue. I do. We disagree. > > jak > > ----- Original Message ----- > From: "Vijay Devarapalli" <[email protected]> > To: "James Kempf" <[email protected]>; "gabriel montenegro" > <[email protected]>; "Yaron Sheffer" > <[email protected]>; "Paul Hoffman" <[email protected]> > Cc: <[email protected]> > Sent: Monday, April 03, 2006 1:41 PM > Subject: RE: [Mobike] Preliminary minutes from the WG last week > > > > > > -----Original Message----- > > From: James Kempf [mailto:[email protected]] > > Sent: Monday, April 03, 2006 1:34 PM > > To: Vijay Devarapalli; gabriel montenegro; Yaron Sheffer; > Paul Hoffman > > Cc: [email protected] > > Subject: Re: [Mobike] Preliminary minutes from the WG last week > > > > For example, listing cases where MOBIKE works with MIP > > Jim, let me know if you have a specific > scenario in mind and if you see an issue. > > also please lookup RFC 4093. it is a > problem statement for VPN traversal with > MIPv4. > > > and > > where not. And > > what to do with route optimization. > > what about route optimization? > > Vijay > > > > > jak > > > > ----- Original Message ----- > > From: "Vijay Devarapalli" <[email protected]> > > To: "James Kempf" <[email protected]>; "gabriel montenegro" > > <[email protected]>; "Yaron Sheffer" > > <[email protected]>; "Paul Hoffman" <[email protected]> > > Cc: <[email protected]> > > Sent: Monday, April 03, 2006 1:14 PM > > Subject: RE: [Mobike] Preliminary minutes from the WG last week > > > > > > > I really think this needs further investigation, particularly > > > in light of > > > the MIP6 transition work. > > > > sure. but I don't see an issue. what are we > > going to investigate? > > > > Vijay > > > > > > > > jak > > > > > > > > > ----- Original Message ----- > > > From: "Vijay Devarapalli" <[email protected]> > > > To: "gabriel montenegro" <[email protected]>; > > > "James Kempf" > > > <[email protected]>; "Yaron Sheffer" > > > <[email protected]>; "Paul > > > Hoffman" <[email protected]> > > > Cc: <[email protected]> > > > Sent: Monday, April 03, 2006 12:23 PM > > > Subject: RE: [Mobike] Preliminary minutes from the WG last week > > > > > > > > > > > > > I'm confused. In the 3GPP2 solution > > > > (draft-ietf-mip4-mobike-connectivity-00) > > > > MOBIKE is not used between MN-HA, right? The separation is: > > > > > > > > between MN-HA: mipv4 tunnel > > > > between MN and VPN gateway: mobike+IPsec > > > > > > right. > > > > > > > Are you folks saying that the above is wrong/discouraged? > > > > > > nope. thats *a* solution for a network where > > > there is a trusted network and an untrusted > > > network with a MIPv4 HA inside the trusted > > > network and a VPN GW in the DMZ. > > > > > > > Or are you saying that it is wrong/discouraged *only* if the > > > > MN-HA is a MIP6/IPsec > > > > tunnel? > > > > > > whats discourage is running MOBIKE and > > > MIP6/IPsec tunnel to the same box. thats my > > > personal opinion anyway. > > > > > > Vijay > > > > > > > > > > > > > > > -gabriel > > > > > > > > --- Vijay Devarapalli <[email protected]> wrote: > > > > > > > > > hi Jim, > > > > > > > > > > with Mobile IPv6, one can create an IPsec > > > > > protected Mobile IP tunnel between the mobile > > > > > node and the home agent. further, the binding > > > > > update is used as a trigger to update the IKE > > > > > SA too. so Mobile IPv6 provides a solution > > > > > similar to MOBIKE already. so that's why I don't > > > > > expect someone to use the two together between > > > > > the mobile node and the home agent. > > > > > > > > > > Mobile IPv4 does not use IPsec and is a very > > > > > different protocol. > > > > > > > > > > Vijay > > > > > > > > > > ps: FYI, the solution described in > > > > > draft-ietf-mip4-mobike-connectivity-00 has > > > > > been adopted by 3GPP2 for their 3GPP2-WLAN > > > > > interworking solution. > > > > > > > > > > > -----Original Message----- > > > > > > From: [email protected] > > > > > > [mailto:[email protected]] On Behalf Of > James Kempf > > > > > > Sent: Monday, April 03, 2006 9:41 AM > > > > > > To: Yaron Sheffer; 'Paul Hoffman'; [email protected] > > > > > > Subject: Re: [Mobike] Preliminary minutes from the WG > > last week > > > > > > > > > > > > Yaron, > > > > > > > > > > > > Thanx for sending out pointers to these. > > > > > > > > > > > > In the MIP6 group, there was some discussion about this, and > > > > > > the message > > > > > > that came up was, in fact, "don't do it". I'll post > > > > > > references to these > > > > > > drafts to the MIP6 list. > > > > > > > > > > > > jak > > > > > > > > > > > > ----- Original Message ----- > > > > > > From: "Yaron Sheffer" <[email protected]> > > > > > > To: "'Paul Hoffman'" <[email protected]>; > > > > <[email protected]> > > > > > > Sent: Sunday, April 02, 2006 3:38 AM > > > > > > Subject: Re: [Mobike] Preliminary minutes from the WG > > last week > > > > > > > > > > > > > > > > > > > Regarding the combination of MOBIKE and Mobile IP, there > > > > > > are 3 current > > > > > > > drafts in MIP4 that deal with this: > > > > > > > > > > > > > > - draft-ietf-mip4-vpn-problem-solution-02 (this one is > > > > pre-MOBIKE) > > > > > > > - draft-ietf-mip4-mobike-connectivity-00 > > > > > > > - draft-meghana-mip4-mobike-optimizations-00 > > > > > > > > > > > > > > So it's a stretch to say "don't do" MOBIKE and Mobile > > > > IP together. > > > > > > > > > > > > > > Yaron > > > > > > > > > > > > > > -----Original Message----- > > > > > > > From: Paul Hoffman [mailto:[email protected]] > > > > > > > Sent: Wednesday, March 29, 2006 5:49 > > > > > > > To: [email protected] > > > > > > > Subject: [Mobike] Preliminary minutes from the WG > last week > > > > > > > > > > > > > > Please let me know if you have any changes. > > > > > > > > > > > > > > MOBIKE WG minutes > > > > > > > IETF 65 > > > > > > > > > > > > > > [deleted] > > > > > > > > > > > > > > James Kempf - discussion in Mobile IP group - what happens > > > > > > if you try to > > > > > > > use Mobile IP and MOBIKE together? Some people believe > > > > the answer is > > > > > > > "don't do that". May need an informational draft (as a new > > > > > > work item) to > > > > > > > address that. > > > > > > > > > > > > > > [deleted] > > > > > > > > > > > > > > > > > > > > > _______________________________________________ > > > > > > > Mobike mailing list > > > > > > > [email protected] > > > > > > > https://www.machshav.com/mailman/listinfo.cgi/mobike > > > > > > > > > > > > > > > > > > > > > > > > > _______________________________________________ > > > > > > Mobike mailing list > > > > > > [email protected] > > > > > > https://www.machshav.com/mailman/listinfo.cgi/mobike > > > > > > > > > > > _______________________________________________ > > > > > Mobike mailing list > > > > > [email protected] > > > > > https://www.machshav.com/mailman/listinfo.cgi/mobike > > > > > > > > > > > > > > > > > __________________________________________________ > > > > Do You Yahoo!? > > > > Tired of spam? Yahoo! Mail has the best spam protection around > > > > http://mail.yahoo.com > > > > > > > > > > > > > _______________________________________________ > > > Mobike mailing list > > > [email protected] > > > https://www.machshav.com/mailman/listinfo.cgi/mobike > > > > > > > > > > > > _______________________________________________ > Mobike mailing list > [email protected] > https://www.machshav.com/mailman/listinfo.cgi/mobike >