RE: New issue 19: Same addresses for both directions?

<[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Atul Sharma wrote:
>
> > Hmm... issue 19 is about asymmetry for IPsec traffic (ESP/AH),
> > not IKEv2/MOBIKE messages (I don't think anyone is proposing 
> > breaking the rule that IKE responses are sent to the same 
> > address the request came from).
> > 
> > If the MOBIKE protocol ends up sending all addresses of both
> > parties in the initial IKE negotiations (IKE_SA_INIT/IKE_AUTH),
> > and each peer selects the addresses for outbound IPsec SAs
> > independently, then conceivably asymmetry could happen 
> > even at that point.
> 
> That would mean in SAD the incoming and outgoing SAs of the
> same SA pair can have different tunnel endpoints. Now that in
> the incoming direction a variation of src,dst addresses can be
> used for searching an SA, we may have to match the src,dst of
> the IPsec traffic in both direction. I do not know if such an
> asymmetry is allowed on IPsec traffic (we agree it is not
> allowed on IKE/MOBIKE traffic).

Hmm... when searching the right SA for inbound (encrypted)
packets, the (outer) src/dst addresses are normally not used 
in rfc2401bis (unless we have SAs where they're multicast
addresses, but that's not possible with IKEv2).

So I don't think there's any fundamental problem in the
asymmetry (but IMHO trying to keep it symmetric probably
will be simpler).

Best regards,
Pasi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.