Re: Re: Lack of packets from other end
Jari Arkko <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Organization | None |
| Message-ID | <[email protected]> |
Tschofenig Hannes wrote: > please note that we are addressing the issue of address changes for ikev2 peers only. we are not talking about fixing problems for entities which do not interact using ike. at the last ietf pasi presented a nice slide which showed the large number of protocols and entities involved in a network. he showed us that we are only addressing a subset of the problems and i agree with him. I agree with this too. And Bora wrote: > I agree with Joe here. There are legitimate situations where > there may be no packets from the other end for a long period > of time. We have DPD to detect a dead peer. If a peer moves > from one IP addr to another without notifying the security > gateway, I don't think it is the SG's job to detect and > recover from this. In fact, it would be *impossible* for the SG to recover from it, because it has no other address for the peer in the case that you mention above. The only question we have on the table is whether an indication from the DPD causes a change in the currently preferred address, *if* the peer has previously indicated that it has several addresses. Past practise (SCTP) and ongoing designs (HIP, MULTI6) all have the approach where the preferred address would be changed in a situation like that. (Another question would be whether the client or the SG needs is responsible for detecting and correcting a choice. I don't want to open that discussion yet, but in general I like the client or the initiator to be responsible for as much as possible, unless protocol symmetry requires otherwise.) --Jari