Re: Re: Lack of packets from other end

Jari Arkko <[email protected]>
Newsgroups gmane.ietf.mobike
Organization None
Message-ID <[email protected]>
Tschofenig Hannes wrote:

> please note that we are addressing the issue of address changes for ikev2 peers only. we are not talking about fixing problems for entities which do not interact using ike. at the last ietf pasi presented a nice slide which showed the large number of protocols and entities involved in a network. he showed us that we are only addressing a subset of the problems and i agree with him.

I agree with this too. And Bora wrote:

> I agree with Joe here. There are legitimate situations where 
> there may be no packets from the other end for a long period 
> of time. We have DPD to detect a dead peer. If a peer moves 
> from one IP addr to another without notifying the security 
> gateway, I don't think it is the SG's job to detect and 
> recover from this.

In fact, it would be *impossible* for the SG to recover
from it, because it has no other address for the peer in the
case that you mention above. The only question
we have on the table is whether an indication from the
DPD causes a change in the currently preferred address,
*if* the peer has previously indicated that it has several
addresses. Past practise (SCTP) and ongoing designs (HIP,
MULTI6) all have the approach where the preferred address
would be changed in a situation like that.

(Another question would be whether the client or the SG
needs is responsible for detecting and correcting a choice.
I don't want to open that discussion yet, but in general
I like the client or the initiator to be responsible for
as much as possible, unless protocol symmetry requires
otherwise.)

--Jari
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.