Re: [Hipsec] ESP in clientVPN tunnel mode - what is needed in exchange
Robert Moskowitz <rgm@htt-consult.com> Tue, 20 May 2014 13:13 UTC
Return-Path: <rgm@htt-consult.com>
X-Original-To: hipsec@ietfa.amsl.com
Delivered-To: hipsec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3A4261A035B for <hipsec@ietfa.amsl.com>; Tue, 20 May 2014 06:13:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level:
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VJi4cWNVCa-J for <hipsec@ietfa.amsl.com>; Tue, 20 May 2014 06:13:44 -0700 (PDT)
Received: from klovia.htt-consult.com (klovia.htt-consult.com [IPv6:2607:f4b8:3:0:218:71ff:fe83:66b9]) by ietfa.amsl.com (Postfix) with ESMTP id C85661A0357 for <hipsec@ietf.org>; Tue, 20 May 2014 06:13:43 -0700 (PDT)
Received: from localhost (unknown [127.0.0.1]) by klovia.htt-consult.com (Postfix) with ESMTP id 829C262B6C; Tue, 20 May 2014 13:13:42 +0000 (UTC)
X-Virus-Scanned: amavisd-new at localhost
Received: from klovia.htt-consult.com ([127.0.0.1]) by localhost (klovia.htt-consult.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6vS6TWlgY6mG; Tue, 20 May 2014 09:13:32 -0400 (EDT)
Received: from lx120e.htt-consult.com (lx120e2.htt-consult.com [208.83.67.155]) (Authenticated sender: rgm@htt-consult.com) by klovia.htt-consult.com (Postfix) with ESMTPSA id 1054962A78; Tue, 20 May 2014 09:13:31 -0400 (EDT)
Message-ID: <537B54FB.1070006@htt-consult.com>
Date: Tue, 20 May 2014 09:13:31 -0400
From: Robert Moskowitz <rgm@htt-consult.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.4.0
MIME-Version: 1.0
To: Miika Komu <mkomu@cs.hut.fi>, hipsec@ietf.org
References: <537A48B6.9030202@htt-consult.com> <537A5313.8090901@cs.hut.fi>
In-Reply-To: <537A5313.8090901@cs.hut.fi>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/hipsec/0NfYPyAqpLiPCKWWC2VqPLnkL7k
Subject: Re: [Hipsec] ESP in clientVPN tunnel mode - what is needed in exchange
X-BeenThere: hipsec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the official IETF Mailing List for the HIP Working Group." <hipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/hipsec>, <mailto:hipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/hipsec/>
List-Post: <mailto:hipsec@ietf.org>
List-Help: <mailto:hipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hipsec>, <mailto:hipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 May 2014 13:13:45 -0000
On 05/19/2014 02:53 PM, Miika Komu wrote: > Hi, > > On 05/19/2014 09:08 PM, Robert Moskowitz wrote: >> I have a real need to provide ESP tunnel mode from a HIP client to a >> gateway. The world just won't go as nicely as I would have wanted it >> to. > > location-based security is old fashioned :( > > At the application layer, tunnel mode may have some implications on > the IPv4-IPv6 interoperability aspects of HIP. I have thought a lot about this, and BOY does it ever mess this up. There would need to be IPv4/v6 signalling within the ESP tunnel to make this work. The VPN interface (separate from the HIP interface) would 'know' if the incoming packet was v4 or v6, and would tag the ESP header appropriately? Or no, wait, not so simple. Actually the addresses ARE in the inner headers, I am getting confused with a HIP proxy that does not maintain an identity for each non-HIP host :) But can ESP tunnel mix and match v4 and v6 inner packets... Oh my head hurts!
- [Hipsec] ESP in clientVPN tunnel mode - what is n… Robert Moskowitz
- Re: [Hipsec] ESP in clientVPN tunnel mode - what … Robert Moskowitz
- Re: [Hipsec] ESP in clientVPN tunnel mode - what … Miika Komu
- Re: [Hipsec] ESP in clientVPN tunnel mode - what … Robert Moskowitz
- Re: [Hipsec] ESP in clientVPN tunnel mode - what … Robert Moskowitz
- Re: [Hipsec] ESP in clientVPN tunnel mode - what … Robert Moskowitz
- [Hipsec] Just use 5203 registration - Re: ESP in … Robert Moskowitz