[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Heartbeats Straw Poll



> >If SGW 1 dies SGW doesn't have a clue about the SPIs that SGW 3 is
> >sending. How he will inform the other end?
> 
> SGW2 could do a Main Mode under any Phase 1 policy that he has to SGW3 and in
> the process, tell him INITIAL-CONTACT.  No subsequent QM's would happen until
> the next packet hits SGW3.  You would want to rate limit this to prevent the
> obvious DoS attack on the receiving side.  

If your policies are certificate/name based rather than address-based,
this might not work so well (since you could have policy allowing
connections from any random address as long as it had the right cert).
I'd rather see schemes which put more of the burden on the peer which
both had state and had traffic to send.

BTW, I think that some sort of "IKE-level ping" facility would be very
useful as a diagnostic tool.  however, it should not be abused as a
"keepalive"/"make-dead" mechanism.

					- Bill


Follow-Ups: References: