Re: [Mip4] Comments on draft-ietf-mip4-dsmipv4-07.txt
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Mip4] Comments on draft-ietf-mip4-dsmipv4-07.txt
...
>
>> > Finally we might need to explain in more detail what happens when the
>> > foreign agent is a VPN gateway as described in RFC 5265. I believe
>> Yaron
>> > raised this issue. In case you set the code in the IPv6 Prefix Reply
>> > Extension to "1" in foreign agent care-of address mode, then the IPv6
>> > packets for the mobile node would actually be encapsulated in an IPsec
>> > tunnel between the MN and the VPN GW, instead of being sent as native
>> > IPv6 packets. So we might need a short paragraph describing this.
>> >
>>
>> GT> We already discussed with Yaron and agreed to add language wrt
>> security devices in general being aware of the new encapsulations
>> defined in this spec.
>
> Can you forward that text, please?
>
Here it is (added at the end of section 5).
"Security devices should look for IPv6 packets encapsulated over
IPv4 either directly to the mobile node's care-of address or via
double encpasulation first to the mobile node's IPv4 home
address and then to the mobile node's care-of addres.
Interactions with Mobile IPv4 and IPsec have been covered
elsewhere, for instance in [RFC5265] and [RFC5266]."
> Vijay
>
--
Mip4 mailing list: Mip4 at ietf.org
Web interface: https://www.ietf.org/mailman/listinfo/mip4
Charter page: http://www.ietf.org/html.charters/mip4-charter.html
Supplemental site: http://www.mip4.org/
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.