I-D Action: draft-mglt-ipsecme-clone-ike-sa-02.txt

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



A New Internet-Draft is available from the on-line Internet-Drafts directories.


        Title           : Clone IKE SA Extension
        Authors         : Daniel Migault
                          Valery Smyslov
	Filename        : draft-mglt-ipsecme-clone-ike-sa-02.txt
	Pages           : 15
	Date            : 2014-07-21

Abstract:
   This document considers a VPN End User setting a VPN with a security
   gateway where at least one of the peers has multiple interfaces.

   With the current IKEv2 protocol, the outer IP addresses of the VPN
   are determined by those used by IKEv2 SA.  As a result using multiple
   interfaces requires to set up an IKEv2 SA on each interface, or on
   each path if both the VPN Client and the security gateway have
   multiple interfaces.  Setting each IKEv2 SA involves authentications
   which might require multiple round trips as well as activity from the
   VPN User and thus would delay the VPN establishment.  In addition
   multiple authentications unnecessarily increase the load on the VPN
   client and the authentication infrastructure.

   This document presents the Clone IKE SA extension, where an
   additional IKEv2 SA is derived from an existing IKEv2 SA.  The newly
   created IKEv2 SA is set without the IKEv2 authentication exchange.
   The newly created IKEv2 SA can later be assigned to another interface
   using MOBIKE protocol.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-mglt-ipsecme-clone-ike-sa/

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-mglt-ipsecme-clone-ike-sa-02

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=draft-mglt-ipsecme-clone-ike-sa-02


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
I-D-Announce mailing list
I-D-Announce@ietf.org
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt




[Index of Archives]     [IETF]     [IETF Discussion]     [Linux Kernel]

  Powered by Linux