Re: [Ipsec] Asymmetric Security
Stephen Kent <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <p0621020bbe373134e5e3@[10.1.190.35]> |
At 10:30 AM -0500 2/11/05, [email protected] wrote: >Hi All, > >I wanted to start a discussion on Asymmetric Security. > >Asymmetry can show up in different ways in a secure transmission. For example: > * we can have asymmetry in the gateways involved in secure >transmission. > * we can have asymmetry in the tunnels between two possible multihomed > gateways > * we can have asymmetry in the tunnel endpoints of the a tunnel > > >(1) Asymmetry in Gateways: >Let us say there are three gateways A, B, C. In the forward >direction secure traffic >flows from Gateway A to Gateway B. In the reverse direction traffic flows from >Gateway C to Gateway A. A Mobile IP End-to-End Security between a >correspondent node and a mobile node will be an example scenario here. >IKE negotiations between A and B can setup a tunnel and IKE negotiations >between C and A can set up the tunnels. Both the tunnels shall still >protect the >same hosts/addresses. [Since IKE negotiations do not allow asymmetry we will >have to have two separate IKE negotiations] so, what's the problem? you have separate SAs because you have different endpoints. we decided long ago to create SAs in pairs. are you concerned that the state maintained for the unused SAs is a unacceptable burden? > >(2) Asymmetry in Tunnels: >Let us say there are two multihomed Gateways. These gateways negotiate TWO >tunnels, each with different tunnel endpoints (corresponding to >multihomed addresses). >But both the tunnels still protecting the same hosts/addresses. This >can be a real >life scenario to acheive redundancy/high availability again, what is the problem here? >(3) Asymmetry in Tunnel Endpoints >Let us say there are two multihome Gateways. These gateways >negotiate ONE tunnel, >but with different tunnel endpoints in forward and reverse >direction. Something recently >discussed in MOBIKE mailing list. as I noted in a separate response, this scenario needs a better description, given the use of terms above. >I wanted to ask folks if current efforts (standards, or >to-be-standards) solve all the >Asymmetry needs of Security? Does it make sense to start new efforts to deal >Asymmetry in Security (ASEC )? > >Should we have a BoF, when we can, to discuss the Asymmetric needs >of Security? I think you have a long way to go before you establish the need for a BoF. Steve