Re: Mobile IP and Mobike

Tero Kivinen <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
James Kempf writes:
> This is certainly not how I use my VPN today and I don't think it would be a
> good idea in any event to design MOBIKE so that it works this way.
> Typically, people use a VPN into a corporate network because they also want
> to derive the benefits of firewall support for external access, not simply
> to access hosts within the corporate LAN. Most client side IPSec VPN
> software grabs the entire network interface and IP stack so that external
> connections are not possible except through the address in the corporate
> network. This is a security measure, otherwise direct attacks on the host
> from the Internet through the local address would be possible. One can
> debate the wisdom of this approach, but the fact of the matter is that many
> corporate VPN users do use it, and most WLAN public access hotspots (which
> provide absolutely no security) assume that something like this scenerio is
> what customers will use (or SSL VPNs, which are another story).

Yes, that is the main scenario of the MOBIKE. Note, that there is no
need for moble IP in that case, which is the reason why I didn't
present this scenario in my last time.

The tunnel mode SA from the SGW to the VPN client, with the IP-address
given from the SGW, and with the MOBIKE updating the tunnel endpoint
addresses as the VPN client moves, is everything which is needed for
mobility for that kind of simple cases. 
-- 
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.