Re: Zero Address Set

Bill Sommerfeld <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <1102352215.7940.69.camel@thunk>
On Mon, 2004-12-06 at 04:16, Tschofenig Hannes wrote:

> i thought about the functionality of the "zero address set". one important
> question is: what is this functionality good for? 

temporary tunnel suspension when the endpoint knows it will be unreachable  for a while.

> i see this issue from a different point of view.
> we have a dead peer detection to provide a mechanism to delete the ike sa
> (and ipsec sas) if the other does not respond anymore. 

well, let's distinguish two cases:
 1) we haven't heard from the peer in a while.
 2) the peer has crashed and forgot about the connection

For some applications, tearing down state because of (1) may rightly viewed  as a bug, not a feature -- but you may want fast recovery from (2) without 
tearing down connections merely because of inactivity.

> if a laptop has establish an ike sa with a gateway, uses dead peer detection
> and goes into the suspend mode then (even after a short amount of time) the
> ike sa will be gone. 
> 
> the 'zero address set' functionality could possibly be seen as temporarily
> suspending the dead peer protection on a specific address (or path). 

Sorta.



						- Bill
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.