Re: issue 34 proposal
Jari Arkko <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
[email protected] wrote: >Hi, > >there is one situation where "dynamic updates" has clear >advantage: voice. Dynamic updates survives much faster >than IKE approach and call would stay up. > >And yes, I know VoIP is out of the scope, but still IPsec is used to >protect voice traffic as well, and if possible that should be taken >into account. > > VoIP is not necessarily out of scope. The group's intention is not to develop a protocol that goes together with a large set of optimizations for various scenarios (like in Mobile IPv6, for instance). But its still OK to choose our base mechanisms in a manner that covers as many application needs as possible, even VoIP. Re: specific issue with dynamic updates. If I recall Pasi's text correctly, it said "SHOULD NOT" for using the dynamic updates -- this means that it would still be possible for, say, a MOBIKE-based IMS phone to go against the SHOULD NOT and use the dynamic updates, given that the importance of this was determined to be high in the given environment. However, I would like to remind that the path testing, MOBIKE mechanisms, DPD, dynamic updates, other L3 mechanisms are not the best option when fast detection is desired. They are necessary when (a) there are no other mechanisms and when (b) problems occur somewhere along the path and not the first link. However, it seems to me that most practical problems occur on the first link and are detectable by L2 indications, IPv6 NUD and the like. Many path problems also have a more permanent nature (e.g., firewall doesn't let you through) that allows them to be avoided by the path test mechanism. In conclusion I think MOBIKE can work pretty efficiently when it comes to first link problems and permanent path problems. The dynamic updates would help, but only in the case of rebooting/forgetful NATs. (I'm not saying thats not important, just trying to quantify the impact.) --Jari