Re: Issue 44: NAT mapping changes and rekeying (was:Comments on draft-ietf-mobike-protocol-03.txt)
"Mohan Parthasarathy" <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <010501c5c885$6b9d6590$6401a8c0@adithya> |
> > >A few comments/questions... > > > > > > - Section 4.4 > > > > > > The initiator receives a NAT_DETECTION_DESTINATION_IP > > > notification that does not match the previous > > > UPDATE_SA_ADDRESSES response (see Section 4.7 for a more > > > detailed description). > > > > > > This does not work reliably when IKE rekeying happens which > > > changes the IKE SPIs. The initiator is behind NAT, creates > > > the IKE SA and notes the down the > > > NAT_DETECTION_DESTINATION_IP notification value (hash of SPI, > > > IP address and port). If rekeying happens sometime later but > > > never received a NAT_DETECTION_DESTINATION_IP or received one > > > before rekeying happened, then the hash may differ because > > > the NAT rebooted causing ports to change OR SPIs changed > > > because of rekeying. How do you tell the difference between > > > the two ? According to section 4.7, the sender SHOULD send > > > UPDATE_SA message. Though there is no harm in sending one, > > > this case should be explained somewhere.. > > > > I think you are correct. I agree though that this does not cause > > a serious problem. > > Hm... yes, this is true. Any suggestions what to do about this? > Would just mentioning this be sufficient? (It doesn't seem > to be a serious problem, especially since IKE_SA rekeying is > not done very frequently.) > Do we really need this functionality ? Why does the initiator need to know explicitly that the NAT mapping has changed ? The initiator behind NAT sends the DPD always with UPDATE_SA_ADDRESS. It should fix it automatically. If it does not, then the PATH is broken. Wouldn't that work ? -mohan > Best regards, > Pasi > > _______________________________________________ > Mobike mailing list > [email protected] > https://www.machshav.com/mailman/listinfo.cgi/mobike