Re: Zero Address Set
"Mohan Parthasarathy" <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <00c801c4dbc4$32a65110$861167c0@adithya> |
Bill, > > i thought about the functionality of the "zero address set". one important > > question is: what is this functionality good for? > > temporary tunnel suspension when the endpoint knows it will be unreachable for a while. > Ok. I can see some use for it. But is zero address set alone sufficient or you also need to tell the other end how long you are not reachable ? Your peer may not want to keep the inactive SAs open for a long time. If you don't specify the time, your peer will delete it anyway after some time. Even if you specify the time, your peer will delete it anyway based on its local configuration (assuming we are not negotiating it). If you don't know how long the SAs will be kept around by your peer, would it still be useful ? -mohan > > i see this issue from a different point of view. > > we have a dead peer detection to provide a mechanism to delete the ike sa > > (and ipsec sas) if the other does not respond anymore. > > well, let's distinguish two cases: > 1) we haven't heard from the peer in a while. > 2) the peer has crashed and forgot about the connection > > For some applications, tearing down state because of (1) may rightly viewed as a bug, not a feature -- but you may want fast recovery from (2) without > tearing down connections merely because of inactivity. > > > if a laptop has establish an ike sa with a gateway, uses dead peer detection > > and goes into the suspend mode then (even after a short amount of time) the > > ike sa will be gone. > > > > the 'zero address set' functionality could possibly be seen as temporarily > > suspending the dead peer protection on a specific address (or path). > > Sorta. > > > > - Bill > > > _______________________________________________ > Mobike mailing list > [email protected] > https://www.machshav.com/mailman/listinfo.cgi/mobike