Re: Dormant Mode?
"James Kempf" <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
> my (somewhat dated, and admittedly limited) experience with demand-dial
> ppp connections leads me to believe that the definition of "gratuitous"
> is often highly user-specific and/or application-specific; if we go down
> this path, will we end up with nodes exchanging specially-marked
> selector sets describing the equivalent of the pppd "active-filter"?
>
Well, some kind of filter is a possibility, but I don't think it is
necessary. The basic requirement, for any kind of Mobike support, is that
the VPN gateway SA timeout is extended, on host request when it is about to
go into dormant mode, so that the host isn't getting frequent keepalives.
> In any event, if we create an operating mode in which NAT keepalives are
> no longer sent, then that will, IMHO, be more-or-less equivalent to a
> no-address-mode scheme --- if you suspend NAT keepalives for longer than
> the NAT's idle-session-destruction timer, you'll essentially lose
> incoming connectivity to the side which is behind that NAT it reasserts
> its presence.
>
I don't see any way to fix the problem with NAT keepalives from the VPN
side, because any keepalive sent to an address owned by the host will get
delivered, thus waking it up, which is what you want to avoid. But I think
it could help in a nonNAT situation.
jak