[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Heartbeats (was RE: keepalives)
>>>>> "Slava" == Slava Kavsan <bkavsan@ire-ma.com> writes:
Slava> Doing heartbeats over IKE SA or IPSec SA is not free - i.e. the
Slava> gateway connected to 1000 Clients needs 1000 addtional heartbeat
Slava> IPSec SAs to negotiate and maintain - very ugly!
I agree.
I would advocate in the gateway->client case sending an ICMP ping to the
client's internal address, from the gateway's internal address on the primary
phase 2 SA. This ought to fit into the typical setup's SPD.
Slava> I am still not convinced about security implications of unsecure
Slava> hearbeats - and would be interested in what people think.
I'm not suggesting that heartbeats be insecure. Rather than IKE needs
something to help debugging.
:!mcr!: | Cow#1: Are you worried about getting Mad Cow Disease?
Michael Richardson | Cow#2: No. I'm a duck.
Home: <A HREF="http://www.sandelman.ottawa.on.ca/People/Michael_Richardson/Bio.html">mcr@sandelman.ottawa.on.ca</A>. PGP key available.
Follow-Ups:
References: