[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IKEv2 and multiple tunnels. (Was: QoS and IKEv2)



Just stirring the soup, food for thought...

> From: "Jesse Alpert" <jalpert@CheckPoint.com>
> 
> In this scenario the "uniquifier" will help, since it will indicate that
> these tunnels are not redundant - they are used by the peer for some
> (unknown) purpose.

SPI itself is already "uniquifier". Maybe the problem is not here, but
instead in the definition of what is "redundant"?

Perhaps it should be changed, remove the following from spec:

> ... is that IKEv2 says that two child-SAs with the same traffic
> selectors are redundant, and extra ones should be closed.

..especially the "should be closed part". The same thing that would
decide whether to include "uniquifier", could also decide whether to
issue DELETE's for the "redundant SA" or not.