Re: Zero Address Set
Bill Sommerfeld <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <1102352215.7940.69.camel@thunk> |
On Mon, 2004-12-06 at 04:16, Tschofenig Hannes wrote: > i thought about the functionality of the "zero address set". one important > question is: what is this functionality good for? temporary tunnel suspension when the endpoint knows it will be unreachable for a while. > i see this issue from a different point of view. > we have a dead peer detection to provide a mechanism to delete the ike sa > (and ipsec sas) if the other does not respond anymore. well, let's distinguish two cases: 1) we haven't heard from the peer in a while. 2) the peer has crashed and forgot about the connection For some applications, tearing down state because of (1) may rightly viewed as a bug, not a feature -- but you may want fast recovery from (2) without tearing down connections merely because of inactivity. > if a laptop has establish an ike sa with a gateway, uses dead peer detection > and goes into the suspend mode then (even after a short amount of time) the > ike sa will be gone. > > the 'zero address set' functionality could possibly be seen as temporarily > suspending the dead peer protection on a specific address (or path). Sorta. - Bill