Re: straw poll on issue 20 (selection ipsec sa addresses andwho decides)

"Mohan Parthasarathy" <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <001701c55cbd$17720590$6501a8c0@adithya>
  > 
>   Option 1: "MOBIKE just informs the peer of our addresses; how
>   they get used is a matter of local policy beyond our scope."
> 
>   Option 2: "Use the preferred/primary address"
> 
>   Option 3: "Initiator decides"
> 
I am assuming that this means that the initiator tests for bidirectional
reachability and then tells the peer about the working address.
One main reason why this seems favorable is because it works well
with NATs and Firewalls. It does not mean that it does not work when
they are not there. But may not work ideally e.g. two SGs connected
and only one of them can decide. So, why build a protocol with
this limitation ?  Does providing an option for either one of them to
choose or both of them to choose complicate the protocol (perhaps
there could be the ping-pong effect of each one changing back and
forth if both of them can choose) ? For example, the initiator says that
it wants to be the deciding factor. The responder knows that the initiator
is not behind a NAT (by looking at NAT-D payloads), then it might be
okay for the responder to choose also, right ? So, the responder can also
choose to be the deciding factor in this case. 

Though i *like* this option, it might make sense to provide some
flexibility for this option.

-mohan


>   Option 4: "Use the preferred/primary address if possible"
> 
>   Option 5: "Peers decide the source addresses independently"
> 
> (There are potential other variants of design but these
> seem to be the main ones, or at least the current concrete
> proposals for the MOBIKE protocol are covered above.)
> 
> Please make your opinion, along with its justifications,
> known by May 25th.
> 
> --Jari
> 
> _______________________________________________
> Mobike mailing list
> [email protected]
> https://www.machshav.com/mailman/listinfo.cgi/mobike
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.