RE: issue 34 proposal
"Stephane Beaulieu (stephane)" <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <13E3DA8B48E17D4C96D261A36A23FCD685F834@xmb-rtp-208.amer.cisco.com> |
> > In your previous mail you wrote: > > Francis Dupont wrote: > > >=> note that I disagree. > > Ok. Can you expand the above a bit with > some reasons and/or alternative proposals? > > => I am for making the standard mechanism for IKEv2/NAT-T > (update by ESP) simply mandatory in MOBIKE environments (option 1bis). > This is not against the charter (no new things for NAT-T) and > can be considered as a MOBIKE profile compatible with the > "mainstream" IKEv2. Francis, Can't both be done? If I notice that packets are coming in using a SPI for which the IP/port doesn't match what I expect, can't I just process them anyway, and update my sadb? There doesn't appear anything interoperability wise to stop you from doing this. If you update, you recover NOW. If you wait for DPD/NAT-T, it will take longer, but still eventually update. It means more code to write (since we have to be able to handle 2 different ways of changing NAT mappings), but it does satisfy both camps. Stephane. > > Regards > > [email protected] > > PS: I don't buy the hardware argument (nor such hardware :-). > _______________________________________________ > Mobike mailing list > [email protected] > https://www.machshav.com/mailman/listinfo.cgi/mobike >