[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[MEXT] new dsmip draft
Folks, I'm forwarding an email from Pasi regarding remaining issues with
the last DSMIP draft. See below.
---------- Forwarded Message ----------
Subject: RE: new dsmip draft
Date: Wednesday 05 March 2008
From: Pasi.Eronen at nokia.com
To: julien.IETF at laposte.net
Some remaining issues:
Section 2.1, QNAME for SRV lookups is *still* wrong.
Section 4.1, identifying the tunneling format (Sebastien
Decugis's comment on mailing list 2008-02-29)
Section 4.1, does not discuss all tunneling formats.
Section 4.1, TLV type value "3" (IPsec), not clear whether
this is ESP or AH (can't detect from packet!).
Section 5, text about switching to port 4500 needs improvement
(so that it's clear at what point switching is done). Also,
I'm not sure if it matters whether the MN is in IPv4 or IPv6
network when the IKE_SA is created -- we need to handle
movements either way later.
Section 5, "When located in an IPv4-only network, the mobile node
MUST NOT negotiate a security association that uses the following
tunnel formats: IPv4/IP(v4 or v6) and IPv4/ESP/IP(v4 or v6)"
IPv4/IPvx (without IPsec) is not really a security association;
and if it must not be negotiated, then the concept of "forcing"
UDP encapsulation (in rest of the document) needs to be removed.
And "MUST NOT negotiate IPv4/ESP/IPvx" is not as simple as that
(it's not really negotiated, but set based on result of NAT
detection).
Section 5.1, I suggested showing packets (both before and after
IPsec processing) would improve readability, but this is not
absolutely required.
The discussion about care-of address mismatch between DSMIPv6
module and IPsec module suggests (incorrectly) that the issue
is just NAT allocating different ports -- like we discussed
earlier, it can also occur later.
Idnits has some errors which look like real errors (not false
positives) to me.
The draft specifies IP-in-something tunneling, but does not
mention words like "fragment", "MTU", or "ECN" (or have any
references which would discuss those) -- that's 100% sure way
to get DISCUSSes from transport ADs. (But if you prefer, you
can wait for the DISCUSSes, too...)
Best regards,
Pasi
_______________________________________________
MEXT mailing list
MEXT at ietf.org
https://www.ietf.org/mailman/listinfo/mext