Re: New issue 16: No packets from other end?

Francis Dupont <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   Francis Dupont writes:
   > => IMHO this is a dangerous path to follow because it shall give
   > a monster for the MOBIKE/IKEv2 tool. I understand you are more interested
   > by MOBIKE SGs than by more generic mobile/multi-homed boxes where
   > MOBIKE is only a small part of the whole thing but please don't
   > specialize MOBIKE as some are always trying to specialize IPsec to VPNs.
   
   The MOBIKE/IKEv2 will be used along with IPsec, I do not even consider
   and option that we would create MOBIKE to be used without IPsec. Most
   of the IPsec implementations already check out the flow if ESP
   packets, and can start actions if they are missing for too long (for
   example IKEv1 you used that for crash recovery and dead peer
   detection).
   
   Why we cannot allow that same mechanism to be used in the MOBIKE? I
   don't think we want to mandate that thing, but we do want to say that
   MOBIKE implementations are allowed to consider the connection to be up
   if there is ESP packets coming from the other end.

=> I believe you missed my point: I have no concern about the mechanism
itself but I have a concern about where it is implemented and as a side
effect how it is specified.

Regards

[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.