[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Heartbeats (was RE: keepalives)




>>>>> "Slava" == Slava Kavsan <bkavsan@ire-ma.com> writes:
    Slava> "Michael C. Richardson" wrote:

    >> I agree.  I would advocate in the gateway->client case sending an ICMP
    >> ping to the client's internal address, from the gateway's internal
    >> address on the primary phase 2 SA. This ought to fit into the typical
    >> setup's SPD.

    Slava> What do you mean by "primary" Phase 2 SA? Does it mean that this
    Slava> IPSec SA should allow ICMP?

  I mean, if you have only one phase 2 SA, then you can use it. If you have
multiple phase 2 SAs, or you have accounting issues, then you shouldn't mind
creating an ICMP-only SA.
  My use of "primary" was confusing.

   :!mcr!:            |  Cow#1: Are you worried about getting Mad Cow Disease?
   Michael Richardson |  Cow#2: No. I'm a duck.
 Home: <A HREF="http://www.sandelman.ottawa.on.ca/People/Michael_Richardson/Bio.html">mcr@sandelman.ottawa.on.ca</A>. PGP key available.




Follow-Ups: References: