issue 34 -- ESP vs. IKE based NAT reboot detection
Jari Arkko <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
I'd like to open discussion on this issue. Please read the slides and notes from http://www3.ietf.org/proceedings/05aug/slides/mobike-2.pdf http://www.machshav.com/pipermail/mobike/2005-August/000912.html and post your thoughts on this issue. As far as I can determine, we are primarily discussing two alternatives: Alt 1: The approach in -01 which retains what IKEv2 does when NAT mappings change. I.e., there's a SHOULD in the IKEv2 spec that allows implementations to update mappings based on what they see happening for the UDP-encapsulated ESP packets. Alt 3: Tero's approach, which says not to use this feature in IKEv2 when MOBIKE is employed, and instead relies on periodic IKE probes. Based on the discussion in IETF-63, it seems that both approaches work, but the tradeoffs are mainly in the area of ease of implementation vs. pressure to decrease probing/keepalive intervals. We do know that there are some (even if few) implementations of IKEv1/v2 that employ the ESP-based check. Similarly, some other implementations aren't doing it. Note also that we need to keep in mind what the requirement level for this feature is or will be. If its not a MUST, this means that whatever bad effect there may be (implementation diffuculties or additional messaging), you do NOT have to suffer from that unless you also need to support this feature. --Jari