comments on draft-ietf-mobike-protocol-01.txt

Shinta Sugimoto <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Hello,

I read draft-ietf-mobike-protocol-01.txt and had following
comments/questions.

Technical Comments/Questions:

- Section 2.3 (Changing addresses in IPsec SAs) I need clarification
  on how address change functions in MOBIKE. First of all, does
  UPDATE_SA_ADDRESSES take effect on more than one address changes ?
  Or it's supposed to update a single address ? Probably I am confusing
  the purpose of UPDATE_SA_ADDRESSES and ADDITIONAL_*_ADDRESS.
  In my understanding, UPDATE_SA_ADDRESSES is for updating the preferred
  address, which means that IKE_SA and IPsec SA (only matched one)
  are the target of the address update. OTOH, ADDITIONAL_*_ADDRESS is
  for updating (requesting its peer to update) the peer address set.
  Do I get it right?
  One more question: Should the initiator make all the CHILD_SAs
  inactive which are associated with the IKE_SA whose "pending_update"
  flag is set ?
- Section 2.7 (NAT prevention), I also felt that better naming is
  needed for NAT_PREVENTED. Taking look at issue #24, I tend to agree
  that NAT_PREVENTED should be replaced with something like
  NAT_PREVENTION_FAILURE from which one can easily understand
  that it's an erroneous state (or failure case).

Editorial Comments:

- Section 2.3 (Changing addresses in IPsec SAs), 3rd bullet, it says
  "If there are outstanding IKEv2 requests, continues retransmitting
  them using the addresses in the IKE_SA (the new addresses)." It is
  unclear to me what the "outstanding IKEv2 requests" are.
- Section 2.4 (Updating additional addresses), the first sentence says
  "both the initiator and responder can send a list of additional
  addresses (in addition to the one used for IKE_SA_INIT/IKE_AUTH
  exchange) to the initiator in the IKE_AUTH exchange." It seems to me
  that the sentence is a bit paradoxical. IMHO, the phrase "to the
  initiator" can be eliminated.


Regards,
Shinta
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.