issue 34 -- ESP vs. IKE based NAT reboot detection

Jari Arkko <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
I'd like to open discussion on this issue. Please read
the slides and notes from

 http://www3.ietf.org/proceedings/05aug/slides/mobike-2.pdf
 http://www.machshav.com/pipermail/mobike/2005-August/000912.html

and post your thoughts on this issue. As far as I can
determine, we are primarily discussing two alternatives:

Alt 1: The approach in -01 which retains what IKEv2 does
when NAT mappings change. I.e., there's a SHOULD in the
IKEv2 spec that allows implementations to update mappings
based on what they see happening for the UDP-encapsulated
ESP packets.

Alt 3: Tero's approach, which says not to use this feature
in IKEv2 when MOBIKE is employed, and instead relies on
periodic IKE probes.

Based on the discussion in IETF-63, it seems that both
approaches work, but the tradeoffs are mainly in the
area of ease of implementation vs. pressure to decrease
probing/keepalive intervals.

We do know that there are some (even if few) implementations
of IKEv1/v2 that employ the ESP-based check. Similarly, some other
implementations aren't doing it.

Note also that we need to keep in mind what the requirement
level for this feature is or will be. If its not a MUST, this means
that whatever bad effect there may be (implementation diffuculties
or additional messaging), you do NOT have to suffer from that
unless you also need to support this feature.

--Jari
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.