[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Heartbeats (was RE: keepalives)




>>>>> "Slava" == Slava Kavsan <bkavsan@ire-ma.com> writes:
    Slava> Doing heartbeats over IKE SA or IPSec SA is not free - i.e. the
    Slava> gateway connected to 1000 Clients needs 1000 addtional heartbeat
    Slava> IPSec SAs to negotiate and maintain - very ugly!

  I agree. 
  I would advocate in the gateway->client case sending an ICMP ping to the
client's internal address, from the gateway's internal address on the primary 
phase 2 SA. This ought to fit into the typical setup's SPD.

    Slava> I am still not convinced about security implications of unsecure
    Slava> hearbeats - and would be interested in what people think.

  I'm not suggesting that heartbeats be insecure. Rather than IKE needs
something to help debugging.

   :!mcr!:            |  Cow#1: Are you worried about getting Mad Cow Disease?
   Michael Richardson |  Cow#2: No. I'm a duck.
 Home: <A HREF="http://www.sandelman.ottawa.on.ca/People/Michael_Richardson/Bio.html">mcr@sandelman.ottawa.on.ca</A>. PGP key available.


Follow-Ups: References: