RE: issue 34 -- ESP vs. IKE based NAT reboot detection

<[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Tero Kivinen writes:
> 
> Bill Sommerfeld writes:
> > Either alternative presumably needs a notification from ESP to 
> > key management that NAT-level "motion" has been detected, but 
> > alternative 3 also seems to require a "mode bit" in ESP 
> > indicating when you should let ESP handle the address updates 
> > and when it should ignore them.
> 
> Not in the ESP, as the ESP is not the one who is going to make the
> change anyways. When the ESP notifies the addresses are changed it
> need to notify about that to the IKE, and at least in our case the
> IKE (usermode policymanager) would be doing that kind of decisions
> when to change and how to change, i.e. it would be then sending
> notification back to the ESP to ask it to modify the outer
> addresses.

The specs don't really say (and even should not say) how this should
be implemented.  Either the ESP module updates the IPsec SAs (and
just notifies the IKE module so that IKE_SA gets updated as well), 
or the ESP module could just notify the IKE module, which would 
then update both IPsec and IKE SAs.

Linux/OpenSWAN uses the latter option, and so does your
implementation, it seems... but concievably, some implementation 
could use the former.

But I'm beginning to think that perhaps your proposal (3) would have
some advantages; at least there would not be two different sources
(ESP and MOBIKE) asking for changes in the addresses...

Best regards,
Pasi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.