[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Heartbeats (was RE: keepalives)
>>>>> "Slava" == Slava Kavsan <bkavsan@ire-ma.com> writes:
Slava> "Michael C. Richardson" wrote:
>> I agree. I would advocate in the gateway->client case sending an ICMP
>> ping to the client's internal address, from the gateway's internal
>> address on the primary phase 2 SA. This ought to fit into the typical
>> setup's SPD.
Slava> What do you mean by "primary" Phase 2 SA? Does it mean that this
Slava> IPSec SA should allow ICMP?
I mean, if you have only one phase 2 SA, then you can use it. If you have
multiple phase 2 SAs, or you have accounting issues, then you shouldn't mind
creating an ICMP-only SA.
My use of "primary" was confusing.
:!mcr!: | Cow#1: Are you worried about getting Mad Cow Disease?
Michael Richardson | Cow#2: No. I'm a duck.
Home: <A HREF="http://www.sandelman.ottawa.on.ca/People/Michael_Richardson/Bio.html">mcr@sandelman.ottawa.on.ca</A>. PGP key available.
Follow-Ups:
References: