RE: [Ipsec] Asymmetric Security

<[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <DC504E9C3384054C8506D3E6BB012460CD8C7D@bsebe001.americas.nokia.com>
Hi Steve,

Some comments/clarifications inline.

Best,
Atul

> -----Original Message-----
> From: ext Stephen Kent [mailto:[email protected]]
> Sent: Tuesday, February 15, 2005 12:05 AM
> To: Sharma Atul (Nokia-ES/Boston)
> Cc: [email protected]; [email protected]
> Subject: Re: [Ipsec] Asymmetric Security
> 
> 
> At 10:30 AM -0500 2/11/05, [email protected] wrote:
> >Hi All,
> >
> >I wanted to start a discussion on Asymmetric Security.
> >
> >Asymmetry can show up in different ways in a secure 
> transmission. For example:
> >	* we can have asymmetry in the gateways involved in secure 
> >transmission.
> >	* we can have asymmetry in the tunnels between two 
> possible multihomed
> >	  gateways
> >	* we can have asymmetry in the tunnel endpoints of the a tunnel
> >
> >
> >(1) Asymmetry in Gateways:
> >Let us say there are three gateways A, B, C. In the forward 
> >direction secure traffic
> >flows from Gateway A to Gateway B. In the reverse direction 
> traffic flows from
> >Gateway C to Gateway A.  A Mobile IP End-to-End Security between a
> >correspondent node and a mobile node will be an example 
> scenario here.
> >IKE negotiations between A and B can setup a tunnel and IKE 
> negotiations
> >between C and A can set up the tunnels. Both the tunnels shall still 
> >protect the
> >same hosts/addresses. [Since IKE negotiations do not allow 
> asymmetry we will
> >have to have two separate IKE negotiations]
> 
> so, what's the problem? you have separate SAs because you have 
> different endpoints. we decided long ago to create SAs in pairs. are 
> you concerned that the state maintained for the unused SAs is a 
> unacceptable burden?

Only that there is no unused SAs or rather no unused SA pairs. There will
be two SA pairs negotiated each with different tunnel endpoints. In the
first SA pair only the forward SA will be used, in the second SA pair only
the reverse SA will be used. Is something like this already allowed?

One SA in each pair shall be unused, which need not even be maintained.

A related question: Do we allow IKE negotiations to be asymmetric, i.e. IKE
message goes to an address, but the response comes back from a different
address?

> >(2) Asymmetry in Tunnels:
> >Let us say there are two multihomed Gateways. These gateways 
> negotiate TWO
> >tunnels, each with different tunnel endpoints (corresponding to 
> >multihomed addresses).
> >But both the tunnels still protecting the same hosts/addresses. This 
> >can be a real
> >life scenario to acheive redundancy/high availability
> 
> again, what is the problem here?

Allowing two tunnels protecting the same addresses/hosts, but with differnt
tunnel endpoints. Is this something allowed now?
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.