RE: Zero Address Set

Tschofenig Hannes <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
hi bill, 

thanks for your quick response. the term 'zero address set' is quite
confusing but i tend to agree with the discussions on the mailing list which
came to the conclusion that this feature should not incorporated into a
mobike protocol. 

the desire to check connectivity (via some sort of message exchange)
periodically has the unpleasant(?) effect that the ike/ipsec sa will be
deleted if one of the peers is not reachable anymore. 

ciao
hannes


> On Mon, 2004-12-06 at 04:16, Tschofenig Hannes wrote:
> 
> > i thought about the functionality of the "zero address set". one 
> > important question is: what is this functionality good for?
> 
> temporary tunnel suspension when the endpoint knows it will 
> be unreachable  for a while.
> 
> > i see this issue from a different point of view.
> > we have a dead peer detection to provide a mechanism to 
> delete the ike 
> > sa (and ipsec sas) if the other does not respond anymore.
> 
> well, let's distinguish two cases:
>  1) we haven't heard from the peer in a while.
>  2) the peer has crashed and forgot about the connection
> 
> For some applications, tearing down state because of (1) may 
> rightly viewed  as a bug, not a feature -- but you may want 
> fast recovery from (2) without tearing down connections 
> merely because of inactivity.
> 
> > if a laptop has establish an ike sa with a gateway, uses dead peer 
> > detection and goes into the suspend mode then (even after a short 
> > amount of time) the ike sa will be gone.
> > 
> > the 'zero address set' functionality could possibly be seen as 
> > temporarily suspending the dead peer protection on a 
> specific address (or path).
> 
> Sorta.
> 
> 
> 
> 						- Bill
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.