Notes
Slide Show
Outline
1
SA Discrepancy Detection for IKEv2
draft-nir-ike-qcd-05
draft-detienne-sir-03
  • Y. Nir
  • F. Detienne
  • P. Sethi


2
What Problem are we Trying to Solve?
  • Detecting de-synchronization of IKE states.
  • When VPN implementations reboot, or otherwise lose their state, their peers need to discover this in order to quickly re-establish the tunnels
  • RFC 4306 and the -bis document describe a method for state loss discovery. However, this method may take several minutes to complete.
    • You need several failed attempts at liveness test before giving up on an IKE SA.
3
What are We Proposing?
  • Our drafts propose an extension to IKEv2 that  securely signal to its peer that it has lost state.
  • When a gateway receives an IKE message with an unknown IKE SPI, it proceeds with an augmented INVALID_IKE_SPI exchange
  • Upon completion, the side with the remaining SA's has sufficient proof that its peer has lost state.
4
What are We Proposing?
  • Design Goals:
    • Minimal persistent state on the peer that lost state.
    • Resistance to attacks (spoofs/DoS)
    • Fast, reactive and event-driven
    • Trigger to initiate IKE SA re-establishment
  • Non Goals:
    • Re-establish the IKE SAs – this can be done using regular IKEv2 or Session Resumption.
    • Discovering the crash before the peer is back online. This cannot be quick.
5
The following slides show the QCD proposed extension

The SIR extension was omitted for brevity
6
QCD Initiation
7
QCD Presentation
8
Do gateways actually lose state?
  • Easy answer: yes.  There are several reasons:
    • Bugs – it's sad, but they do exist.
    • OS failures.
    • Power failures – try running a gateway without UPS in Detroit.
    • Temporary connectivity failures, where only one side is doing regular liveness checks.
    • Scheduled maintenance with or without a backup gateway.
    • The administrator's favorite button for trouble-shooting (and it really helps, too! - see next slide)
    • Load (re)balancing
9
Reset All the Tunnels!
  • Every implementation has a command like this:
    • clear crypto isakmp sa
    • clear services ipsec-vpn ike security-associations
    • fw tab -t ikev2_sas -x -y
    • ipsec restart
    • setkey -F ; killall racoon
  • For extra credit, identify these implementations!
10
Why this should be a WG item?
  • Has security implications – needs eyeballs.
  • Has interaction with other WG items:
    • Session Resumption
  • Has interaction with non-IETF standards:
    • 3GPP
  • Fills a need for multiple vendors and users of IKE.
  • Serious improvement of user experience
  • Two competing proposals