RE: RE: [Ipsec] Asymmetric Security

"Srinivasa Rao Addepalli" <[email protected]>
Newsgroups gmane.ietf.mobike
Organization Intoto Inc
Message-ID <[email protected]>
Hi Atul,

> >(1) Asymmetry in Gateways:
> >Let us say there are three gateways A, B, C. In the forward 
> >direction secure traffic
> >flows from Gateway A to Gateway B. In the reverse direction 
> traffic flows from
> >Gateway C to Gateway A.  A Mobile IP End-to-End Security between a
> >correspondent node and a mobile node will be an example 
> scenario here.
> >IKE negotiations between A and B can setup a tunnel and IKE 
> negotiations
> >between C and A can set up the tunnels. Both the tunnels shall still 
> >protect the
> >same hosts/addresses. [Since IKE negotiations do not allow 
> asymmetry we will
> >have to have two separate IKE negotiations]
> 
> so, what's the problem? you have separate SAs because you have 
> different endpoints. we decided long ago to create SAs in pairs. are 
> you concerned that the state maintained for the unused SAs is a 
> unacceptable burden?

Only that there is no unused SAs or rather no unused SA pairs. There will
be two SA pairs negotiated each with different tunnel endpoints. In the
first SA pair only the forward SA will be used, in the second SA pair only
the reverse SA will be used. Is something like this already allowed?

SRINI> This scenario happens even in cases where each peer having only one
IP address. Think of a scenario, where both parties re-key IPsec (phase2)
keys at the same time. So, IMO the scenario you described would work with
existing implementations.

One SA in each pair shall be unused, which need not even be maintained.

A related question: Do we allow IKE negotiations to be asymmetric, i.e. IKE
message goes to an address, but the response comes back from a different
address?

SRINI> In my view, this may not be problem with IKE implementations. But, we
observed this problem, when there is symmetric firewall in between IKE
peers. It is a good practice that IKE implementations send the
reverse/response IKE packets with source IP address as the landed IP address
of the received IKE packet. So, I consider the problem you indicated is more
of implementation problem than the specification limitation.

> >(2) Asymmetry in Tunnels:
> >Let us say there are two multihomed Gateways. These gateways 
> negotiate TWO
> >tunnels, each with different tunnel endpoints (corresponding to 
> >multihomed addresses).
> >But both the tunnels still protecting the same hosts/addresses. This 
> >can be a real
> >life scenario to acheive redundancy/high availability
> 
> again, what is the problem here?

Allowing two tunnels protecting the same addresses/hosts, but with differnt
tunnel endpoints. Is this something allowed now?

SRINI> Yes, specifications don't prohibit this behavior. It is already put
to use, in implementations, to achieve load sharing of the data across
multiple SAs to pass secured traffic through multiple WAN links.



_______________________________________________
Mobike mailing list
[email protected]
https://www.machshav.com/mailman/listinfo.cgi/mobike
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.