[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Heartbeats Straw Poll



 >If SGW 1 dies SGW doesn't have a clue about the SPIs that SGW 3 is
 >sending. How he will inform the other end?

SGW2 could do a Main Mode under any Phase 1 policy that he has to SGW3 and in
the process, tell him INITIAL-CONTACT.  No subsequent QM's would happen until
the next packet hits SGW3.  You would want to rate limit this to prevent the
obvious DoS attack on the receiving side.  Our product implements this and it
works well.  (Of course, our clustered gateways have replicated IKE state, so
this is a non-problem for most of our customers.)

Derrell






Follow-Ups: References: