RE: Zero Address Set
Tschofenig Hannes <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
hi bill, thanks for your quick response. the term 'zero address set' is quite confusing but i tend to agree with the discussions on the mailing list which came to the conclusion that this feature should not incorporated into a mobike protocol. the desire to check connectivity (via some sort of message exchange) periodically has the unpleasant(?) effect that the ike/ipsec sa will be deleted if one of the peers is not reachable anymore. ciao hannes > On Mon, 2004-12-06 at 04:16, Tschofenig Hannes wrote: > > > i thought about the functionality of the "zero address set". one > > important question is: what is this functionality good for? > > temporary tunnel suspension when the endpoint knows it will > be unreachable for a while. > > > i see this issue from a different point of view. > > we have a dead peer detection to provide a mechanism to > delete the ike > > sa (and ipsec sas) if the other does not respond anymore. > > well, let's distinguish two cases: > 1) we haven't heard from the peer in a while. > 2) the peer has crashed and forgot about the connection > > For some applications, tearing down state because of (1) may > rightly viewed as a bug, not a feature -- but you may want > fast recovery from (2) without tearing down connections > merely because of inactivity. > > > if a laptop has establish an ike sa with a gateway, uses dead peer > > detection and goes into the suspend mode then (even after a short > > amount of time) the ike sa will be gone. > > > > the 'zero address set' functionality could possibly be seen as > > temporarily suspending the dead peer protection on a > specific address (or path). > > Sorta. > > > > - Bill > >