RE: RE: [Ipsec] Asymmetric Security
"Srinivasa Rao Addepalli" <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Organization | Intoto Inc |
| Message-ID | <[email protected]> |
Hi Atul, > >(1) Asymmetry in Gateways: > >Let us say there are three gateways A, B, C. In the forward > >direction secure traffic > >flows from Gateway A to Gateway B. In the reverse direction > traffic flows from > >Gateway C to Gateway A. A Mobile IP End-to-End Security between a > >correspondent node and a mobile node will be an example > scenario here. > >IKE negotiations between A and B can setup a tunnel and IKE > negotiations > >between C and A can set up the tunnels. Both the tunnels shall still > >protect the > >same hosts/addresses. [Since IKE negotiations do not allow > asymmetry we will > >have to have two separate IKE negotiations] > > so, what's the problem? you have separate SAs because you have > different endpoints. we decided long ago to create SAs in pairs. are > you concerned that the state maintained for the unused SAs is a > unacceptable burden? Only that there is no unused SAs or rather no unused SA pairs. There will be two SA pairs negotiated each with different tunnel endpoints. In the first SA pair only the forward SA will be used, in the second SA pair only the reverse SA will be used. Is something like this already allowed? SRINI> This scenario happens even in cases where each peer having only one IP address. Think of a scenario, where both parties re-key IPsec (phase2) keys at the same time. So, IMO the scenario you described would work with existing implementations. One SA in each pair shall be unused, which need not even be maintained. A related question: Do we allow IKE negotiations to be asymmetric, i.e. IKE message goes to an address, but the response comes back from a different address? SRINI> In my view, this may not be problem with IKE implementations. But, we observed this problem, when there is symmetric firewall in between IKE peers. It is a good practice that IKE implementations send the reverse/response IKE packets with source IP address as the landed IP address of the received IKE packet. So, I consider the problem you indicated is more of implementation problem than the specification limitation. > >(2) Asymmetry in Tunnels: > >Let us say there are two multihomed Gateways. These gateways > negotiate TWO > >tunnels, each with different tunnel endpoints (corresponding to > >multihomed addresses). > >But both the tunnels still protecting the same hosts/addresses. This > >can be a real > >life scenario to acheive redundancy/high availability > > again, what is the problem here? Allowing two tunnels protecting the same addresses/hosts, but with differnt tunnel endpoints. Is this something allowed now? SRINI> Yes, specifications don't prohibit this behavior. It is already put to use, in implementations, to achieve load sharing of the data across multiple SAs to pass secured traffic through multiple WAN links. _______________________________________________ Mobike mailing list [email protected] https://www.machshav.com/mailman/listinfo.cgi/mobike