[Dime] Defining a new Application for mip6-split ?
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Dime] Defining a new Application for mip6-split ?



Hi all,

 we're in the process of updating/writing the document describing use of
 Diameter for the Mobile IPv6 split scenario.

 In the split scenario, the Mobile Node (MN) uses IKEv2 with the HA to
 setup IPsec SAs. This exchange is also used by the HA to authenticate
 the MN using EAP. The HA may rely on a AAA/EAP server for this. So we
 have the following scheme:

 MN <-- IKEv2-EAP --> HA <--------> AAA

 A priori Diameter EAP (RFC 4072) can be used between HA and AAA. 

 The problem is that Diameter EAP is normally used for Network Access
 authentication. 

 In our case, the AAA server must perform AAA functionality for the
 Mobile IPv6 service. The AAA server must know that it has to authorize
 the mip6 service and the accounting (ASR/ASA) is also for mip6 and not
 for network access.

 For the above reason, it seems that we should define a new Diameter
 Application. However, in the same time, the messages defined in
 Diameter EAP could be reused.

 So I'd like to hear opinions concerning this issue.

 Thanks,


 - Julien B.


_______________________________________________
DiME mailing list
DiME at ietf.org
https://www1.ietf.org/mailman/listinfo/dime




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.