Re: issue 34 -- ESP vs. IKE based NAT reboot detection

Tero Kivinen <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Bill Sommerfeld writes:
> Either alternative presumably needs a notification from ESP to key
> management that NAT-level "motion" has been detected, but alternative 3
> also seems to require a "mode bit" in ESP indicating when you should let
> ESP handle the address updates and when it should ignore them.

Not in the ESP, as the ESP is not the one who is going to make the
change anyways. When the ESP notifies the addresses are changed it
need to notify about that to the IKE, and at least in our case the IKE
(usermode policymanager) would be doing that kind of decisions when
to change and how to change, i.e. it would be then sending
notification back to the ESP to ask it to modify the outer addresses.

In case mobike, the usermode policymanager would not send those
notifications, and with normal IKEv2 NAT-T it could send those
(depending on the policy).

If the NAT-T updating is supported, then the change needs to be done
in both ESP and IKE SAs regardless which one of those detect the
change (and depending on the policy). I am pretty much sure that there
are people who want to disable that, or do it only partially (i.e.
only update port, but not address etc) and all this depends on policy.
-- 
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.