Re: issue #16
Joe Touch <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jari Arkko wrote: | Hi Joe, | |> While I appreciate that IKE should retry, or allow reconecting, which |> could involve different addresses (i.e., different source address used |> on retry/restart), managing the addresses seems like it should be a |> side-effect of the restart (leave the source address blank, let it be |> filled in on exit) rather than explicitly managed. | | Do I interpret you correctly if I say that | | (1) You are OK with explicit management of addresses | when we have local information from the other | parts of the stack that we need to do something, | such as when the currently used link went down, | ND tells us that we have moved to a new address, | and so on. Not quite - I don't buy the part about the 'link going down'. All you know is that the other end isn't reachable. Reacting to links is what dynamic routing does; if this layer does it as well, there's liable to be interactions (in a bad way). | (2) You are NOT OK with explicit management when | DPD fails. DPD failing means you can't talk to the other end, which means - IMO - that the mapping you used before (name -> addr) is no longer working. Trying a new mapping, or cycling among alternate names ought to happen when IKE starts anyway (at the app layer). | If this is correct, this would still leave us a | few questions, such as | | o What about other things than direct local knowledge | that we may get from the rest of the stack. For instance, | would explicit management be OK if you get persistent | ICMP errors, do a DPD because of them, and then get | a failure? It depends on what the errors are. Some warrant a restart, some do not. But, IMO, they warrant restart of the IKE. | o What does side-effect mean, exactly? Do you mean to | say that the sender can choose any source address, as | long as the selection is done by something lower in the | stack than IKE? Or do you mean that source address | selection is OK but destination address selection is not. | Or something else? More that cycling among alternate addrs is something that ought to happen on start anyway - side-effect isn't quite the right term; it's more like 'already included explicit mechanism'. Joe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFBw28WE5f5cImnZrsRAsICAKCx1zU1gHQODPfXQURRowQNDTUpRQCgqlUu XfipqdYdADQSK3UTfkQGt4A= =u2kr -----END PGP SIGNATURE-----