Re: Preliminary minutes from the WG last week
Jari Arkko <[email protected]> Tue, 04 Apr 2006 09:37:46 +0300
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Vijay Devarapalli wrote: >hi Jim, > >with Mobile IPv6, one can create an IPsec >protected Mobile IP tunnel between the mobile >node and the home agent. further, the binding >update is used as a trigger to update the IKE >SA too. so Mobile IPv6 provides a solution >similar to MOBIKE already. so that's why I don't >expect someone to use the two together between >the mobile node and the home agent. > > Personally, I am not as convinced as you are that they should never be used together to the same box. What if the client is on a v4 network? Or on two separate connections, including mixed v4/v6 and NATs. Popping up a level, it seems like some combination of IKE/MOBIKE/NAT-T, Mobile IPv6, Mobile IPv6 transition mechanisms, and MONAMI6 should be able to cover the following situations and combinations of them: - Having a separate SGW before you can reach your HA - Integrated SGW/HA - IPv4 access networks - IPv6 access networks - NATs and firewalls - Multihomed mobile nodes - Mobile nodes that you cannot fully trust (e.g. might need a RR before believing their new location) - Mobile IPv6 service that requires EAP authentication What exact combination of solutions we should use is less clear to me. But I confess that I haven't read the most recent documents on Mobile IPv6 transition mechanisms. Anyway, as Paul said maybe someone who cares needs to write a document about this... --Jari