Re: Dormant Mode?
Jari Arkko <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Good question. I think we made a decision earlier on that we will not support what we called "zero address set" mode, where the client notifies the other end that its temporarily unreachable. I'd rather not reopen that discussion. However, this is not the same as providing a protocol that is suitable even to peers going dormant. For instance, it might be an idea to provide specification guidance or even some informational data over the protocol about the characteristics of the peer at the other end. This could also be done as an orthogonal function to the base MOBIKE protocol exchange. (Also, we'd probably want to stay away from re-introducing lifetimes that were removed when going from IKEv1 to IKEv2.) --Jari James Kempf wrote: > So I'd like to raise a possible issue here, namely whether or not > Mobike should attempt to support dormant mode hosts. I say that it's a > "possible" issue because, in general, most IETF protocols don't do a > very good job supporting dormant mode, and it would be entirely > consistent to say that Mobike doesn't either. But I think the point > should at least be raised. > > Section 2.4 of draft-ietf-ipsec-ikev2-17.txt (IKEv2 spec) has some > guidance about connection timers, but there is nothing specific about > recommended values for timeouts or retransmissions, since, as the > document correctly notes, this will vary depending on circumstance. > Since some mobile hosts can actually spend more time in dormant mode > than active, for power saving purposes, there's a possibility that the > IKE SAs will need to be regenerated from scratch every time the mobile > host comes out of dormant mode, if the timeouts are set too short. In > addition, if there are any stateful middleboxes (proxies, firewalls), > the state on them could expire prematurely, causing a request incoming > through the VPN tunnel gateway to be rejected even though the VPN > tunnel gateway itself didn't time out the SA. > > The basic issue I think that needs addressing is: should Mobike > attempt in some way to address dormant mode, since, like address > changes, it is a characteristic of mobile hosts? > > Thoughts? > > jak > > _______________________________________________ > Mobike mailing list > [email protected] > https://www.machshav.com/mailman/listinfo.cgi/mobike > >