[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Heartbeats Straw Poll
On Mon, 07 Aug 2000 18:00:33 +0200 you wrote
> "Derrell D. Piper" wrote:
> > >If SGW 1 dies SGW doesn't have a clue about the SPIs that SGW 3 is
> > >sending. How he will inform the other end?
> > SGW2 could do a Main Mode under any Phase 1 policy that he has to SGW3 and
> > the process, tell him INITIAL-CONTACT. No subsequent QM's would happen unt
> > the next packet hits SGW3. You would want to rate limit this to prevent th
> > obvious DoS attack on the receiving side. Our product implements this and
> > works well. (Of course, our clustered gateways have replicated IKE state,
> > this is a non-problem for most of our customers.)
> Fine... but how does SGW3 know it has to negotiate new phase 2 SA's with SGW2
> ? If the traffic is one way (from sgw3 to sgw1/2), SGW2 will never ask the ri
>ght SA's to be re-created (how would SGW2 know what it could not decrypt)...
That's what the INITIAL-CONTACT notification is for.