Re: When to do Return Routability Checks
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote: this is issue is interesting. in a previous mail i had the impression that you argued that only an authorized address can be used for communication (non-return-routability-test messages). => not exactly because IMHO return-routability-test messages can be a way to authorize an address, so there can be a case, likely limited to return-routability-test messages, where a not yet authorized address may be used for communications. if you have an unauthorized address you need to perform some authorization check (which might require a return routability check) to turn this address into an authorized address which can subsequently be used. => exactly. Note the authorization is required only for IPsec packets, for IKE messages connectivity is more important. if my observation is correct then you also suggest to have a window larger than one in order for the protocol to work. => IMHO this is not necessary but highly recommended (i.e., SHOULD). Thanks [email protected]