Re: issue 34 -- ESP vs. IKE based NAT reboot detection
Tero Kivinen <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Bill Sommerfeld writes: > Either alternative presumably needs a notification from ESP to key > management that NAT-level "motion" has been detected, but alternative 3 > also seems to require a "mode bit" in ESP indicating when you should let > ESP handle the address updates and when it should ignore them. Not in the ESP, as the ESP is not the one who is going to make the change anyways. When the ESP notifies the addresses are changed it need to notify about that to the IKE, and at least in our case the IKE (usermode policymanager) would be doing that kind of decisions when to change and how to change, i.e. it would be then sending notification back to the ESP to ask it to modify the outer addresses. In case mobike, the usermode policymanager would not send those notifications, and with normal IKEv2 NAT-T it could send those (depending on the policy). If the NAT-T updating is supported, then the change needs to be done in both ESP and IKE SAs regardless which one of those detect the change (and depending on the policy). I am pretty much sure that there are people who want to disable that, or do it only partially (i.e. only update port, but not address etc) and all this depends on policy. -- [email protected]