Re: Asymmetric Security

Yoav Nir <[email protected]>
Newsgroups gmane.ietf.ipsec,gmane.ietf.mobike
Message-ID <[email protected]>
I would add a fourth scenario, which is actually a variation.

(4) Asymmetry in clustered gateways
Let us say that there are several gateways (call them A1 and A2) that 
appear to be a single gateway (i.e, have one identifier, one 
certificate, one IP address) with some load-sharing clustering hardware 
or software.  Any peer (call it C) must never see anything other than a 
single gateway (call it A).  The problem is that due to performance 
constraints, the two gateways cannot synchronize their state after 
every packet, and because of the retransmission counter of ESP, they 
need to have two SAs, one for A1 and one for A2.  In IKEv1 this was a 
problem, because IKE implementations were not required to support 
multiple redundant SAs (and to C, it looks like the two SAs are 
redundant).  Such implementations always deleted one of the SAs.  In 
IKEv2 C is required to support multiple redundant SAs.

On Feb 11, 2005, at 5:30 PM, [email protected] wrote:

> Hi All,
>
> I wanted to start a discussion on Asymmetric Security.
>
> Asymmetry can show up in different ways in a secure transmission. For 
> example:
> 	* we can have asymmetry in the gateways involved in secure 
> transmission.
> 	* we can have asymmetry in the tunnels between two possible multihomed
> 	  gateways
> 	* we can have asymmetry in the tunnel endpoints of the a tunnel
>
>
> (1) Asymmetry in Gateways:
> Let us say there are three gateways A, B, C. In the forward direction 
> secure traffic
> flows from Gateway A to Gateway B. In the reverse direction traffic 
> flows from
> Gateway C to Gateway A.  A Mobile IP End-to-End Security between a
> correspondent node and a mobile node will be an example scenario here.
> IKE negotiations between A and B can setup a tunnel and IKE 
> negotiations
> between C and A can set up the tunnels. Both the tunnels shall still 
> protect the
> same hosts/addresses. [Since IKE negotiations do not allow asymmetry 
> we will
> have to have two separate IKE negotiations]
>
> (2) Asymmetry in Tunnels:
> Let us say there are two multihomed Gateways. These gateways negotiate 
> TWO
> tunnels, each with different tunnel endpoints (corresponding to 
> multihomed addresses).
> But both the tunnels still protecting the same hosts/addresses. This 
> can be a real
> life scenario to acheive redundancy/high availability
>
> (3) Asymmetry in Tunnel Endpoints
> Let us say there are two multihome Gateways. These gateways negotiate 
> ONE tunnel,
> but with different tunnel endpoints in forward and reverse direction. 
> Something recently
> discussed in MOBIKE mailing list.
>
>
> I wanted to ask folks if current efforts (standards, or 
> to-be-standards) solve all the
> Asymmetry needs of Security? Does it make sense to start new efforts 
> to deal
> Asymmetry in Security (ASEC )?
>
> Should we have a BoF, when we can, to discuss the Asymmetric needs of 
> Security?
>
>
> Atul
>
>
>
> _______________________________________________
> Ipsec mailing list
> [email protected]
> https://www1.ietf.org/mailman/listinfo/ipsec
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.