Re: straw poll on issue 20 (selection ipsec sa addresses andwho decides)

Jari Arkko <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Hi Mohan,

>I am assuming that this means that the initiator tests for bidirectional
>reachability and then tells the peer about the working address.
>One main reason why this seems favorable is because it works well
>with NATs and Firewalls. It does not mean that it does not work when
>they are not there. But may not work ideally e.g. two SGs connected
>and only one of them can decide. So, why build a protocol with
>this limitation ?  Does providing an option for either one of them to
>choose or both of them to choose complicate the protocol (perhaps
>there could be the ping-pong effect of each one changing back and
>forth if both of them can choose) ? For example, the initiator says that
>it wants to be the deciding factor. The responder knows that the initiator
>is not behind a NAT (by looking at NAT-D payloads), then it might be
>okay for the responder to choose also, right ? So, the responder can also
>choose to be the deciding factor in this case. 
>  
>
I'm not sure if this is what you were looking for, but
the peers do have some ability to select who decides,
simply by choosing who is the initiator... and if you
don't like the initial arrangement, you could presumably
take the current connection down and re-initiate yourself.

--Jari
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.