Re: [IPsec] draft-xu-ipsecme-esp-in-udp-lb-07

"Bottorff, Paul" <paul.bottorff@hpe.com> Fri, 02 April 2021 21:59 UTC

Return-Path: <prvs=0726bc5a0e=paul.bottorff@hpe.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7DF833A2550 for <ipsec@ietfa.amsl.com>; Fri, 2 Apr 2021 14:59:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.119
X-Spam-Level:
X-Spam-Status: No, score=-2.119 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=hpe.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xoXZTTlKOiYv for <ipsec@ietfa.amsl.com>; Fri, 2 Apr 2021 14:59:16 -0700 (PDT)
Received: from mx0b-002e3701.pphosted.com (mx0b-002e3701.pphosted.com [148.163.143.35]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 443553A254F for <ipsec@ietf.org>; Fri, 2 Apr 2021 14:59:15 -0700 (PDT)
Received: from pps.filterd (m0150245.ppops.net [127.0.0.1]) by mx0b-002e3701.pphosted.com (8.16.0.43/8.16.0.43) with SMTP id 132LwhEf008782; Fri, 2 Apr 2021 21:59:15 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hpe.com; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : content-transfer-encoding : mime-version; s=pps0720; bh=kc8AB5kvMuCwjkrOW5Mn3XU71gJQB407TYI3Oazzjh0=; b=ctEfD96dR88KK/iItGDQ9LO/e5ofHs22p67qQf7pgRZtXzbb6XiyAA+ZOiMiG77FSuvT AP4e7PBttXrUtrOYJFHtQcLuCC6g7ZkyXu9u1D3gpd4L1+AhKwVzYhUwnTlDWQkC7kfJ N0OAhhYzSmldJItnSe0Oplic1GjpFUMZ3HbLTbo8egScZeLkZAXUCHlvRbnGVsqg+CeV Z1yVUvq4qT4VAaKheMD+eJ3LDjNeAx03R+aMQhTz4yqm64qW9GRMjEINmzSUVfTmVa1l jPxzFRPrrmlf9ZYch7KsAX2vSLhy8VbAL67gEzNULViJmlwYbaEipyHVSs1L/3TopNLG WQ==
Received: from g2t2352.austin.hpe.com (g2t2352.austin.hpe.com [15.233.44.25]) by mx0b-002e3701.pphosted.com with ESMTP id 37pafm0enn-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 02 Apr 2021 21:59:14 +0000
Received: from G9W8454.americas.hpqcorp.net (exchangepmrr1.us.hpecorp.net [16.216.161.4]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by g2t2352.austin.hpe.com (Postfix) with ESMTPS id E52C69B; Fri, 2 Apr 2021 21:59:13 +0000 (UTC)
Received: from G2W6310.americas.hpqcorp.net (2002:10c5:4034::10c5:4034) by G9W8454.americas.hpqcorp.net (2002:10d8:a104::10d8:a104) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Fri, 2 Apr 2021 21:59:13 +0000
Received: from NAM10-MW2-obe.outbound.protection.outlook.com (15.241.52.13) by G2W6310.americas.hpqcorp.net (16.197.64.52) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Fri, 2 Apr 2021 21:59:13 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=E2l0YLfuU3Nuri9GCanNyjHQPBdeSXW4yg/9RSPI+Cr+YEW58JMFgLk/P5OFRf0s/3MOmXNmYHxZH4UZDheMRjGk2j5LwN/btvvuMWBUG3fLldoFDA8z/2cP5e072ZWLGBFzX4kXFekltaN+rfKq3zJQqtF/eQW8/nNZF9iaY5xgcyx1s41H0fXZGvzr+M115n+EDXyqgA7DCmbWfpPj5y4r4GNVKG58V+s3DQhZytud0lapn+XmBfYCx00jHtgXgtGBNkTPa4nnivj+L0SYyJZy6PkFstE/7YrGMMgidh0JSeGl7ztKO2YM4r4gcdwuU/lAYo3f/sBQU+UorNTvPA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=zdmaf61NT3qXEs7I8Ghtueu48YQRxsiFUl5qTH/2O/0=; b=eYBEiCXahYaOMsNWg+pmX3niqxx4wcgVIA+Ez5+4hCxKQuMLFTVIQYL9af6Ux6dwLIjqLVBNGV0IaunlWMssEdSTNg1dJHPsXRuiicSGp1IETg1f6Q6NtlOv1lqbtmsRwx/mu71JrBH5xV+a9Hz/aNmGDLihbBNgJIi7kEOqJysMgBVZJUoouw/k/8BKgGlflBAFoLxjp90J57BBH/eRaiDhyKS+UN+fOsyRas5+J8f6egwBpgmGI7E8oBBBVsux4Zl2Frs7HDtHKdzF4k5ETdOrtiC+hSt1dAu1dfmzfGlsuvaenjaPOXc8whrd5wxjmbnQGJhQrgwvnHE/Lh+YcA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=hpe.com; dmarc=pass action=none header.from=hpe.com; dkim=pass header.d=hpe.com; arc=none
Received: from CS1PR8401MB1192.NAMPRD84.PROD.OUTLOOK.COM (2a01:111:e400:7507::23) by CS1PR8401MB0853.NAMPRD84.PROD.OUTLOOK.COM (2a01:111:e400:750e::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3999.29; Fri, 2 Apr 2021 21:59:12 +0000
Received: from CS1PR8401MB1192.NAMPRD84.PROD.OUTLOOK.COM ([fe80::bd7d:6948:a6d3:c04]) by CS1PR8401MB1192.NAMPRD84.PROD.OUTLOOK.COM ([fe80::bd7d:6948:a6d3:c04%5]) with mapi id 15.20.3999.029; Fri, 2 Apr 2021 21:59:12 +0000
From: "Bottorff, Paul" <paul.bottorff@hpe.com>
To: Valery Smyslov <smyslov.ietf@gmail.com>, 'Tero Kivinen' <kivinen@iki.fi>
CC: 'IPsec' <ipsec@ietf.org>, "antony.antony@secunet.com" <antony.antony@secunet.com>
Thread-Topic: [IPsec] draft-xu-ipsecme-esp-in-udp-lb-07
Thread-Index: AdciaiROLLoGnn3oQyW5+9ys0PMxKgJRErFpANOS/JYCNRDTH6tGNXFQq2XEr5A=
Date: Fri, 02 Apr 2021 21:59:12 +0000
Message-ID: <CS1PR8401MB11924CD1BF4CC233523180F3FE7A9@CS1PR8401MB1192.NAMPRD84.PROD.OUTLOOK.COM>
References: <CS1PR8401MB11928BE251D4B6E05184D941FE619@CS1PR8401MB1192.NAMPRD84.PROD.OUTLOOK.COM> <20210331103220.GA21137@moon.secunet.de> <CS1PR8401MB119267E038AFBDFD996F0441FE7C9@CS1PR8401MB1192.NAMPRD84.PROD.OUTLOOK.COM> <24678.19440.553333.890224@fireball.acr.fi> <036401d72786$91047b90$b30d72b0$@gmail.com>
In-Reply-To: <036401d72786$91047b90$b30d72b0$@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=hpe.com;
x-originating-ip: [165.225.243.15]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 44aa9f96-417b-41ab-93bc-08d8f6228ccb
x-ms-traffictypediagnostic: CS1PR8401MB0853:
x-microsoft-antispam-prvs: <CS1PR8401MB08532CF3D1CE0923463A5496FE7A9@CS1PR8401MB0853.NAMPRD84.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: Hlt37O4JcScXaaIibgHKJAkOrtwXnIEaSo3tm+rQtGefhB0NL3ezE8o7sO8pfcorWKRAl5NeRMO4m9QYHlgddtprjbYRWQVVYElgZGN9DJcPD1b9ir3DKNVx3IVCqGPKprSbtfDuklvz+F5EYzvg4jiPkM77md4GC0dKYESruXuzk1Y8HYamN/a1DVv68bSRxSmy9KYIukitNiel299OFFsgGkMGEUjC7/UgSfwMw+4MByv7jmLYG5KY8iiZ1yH+w5xBO0ZXirbktPyU9w+TgkMRtlwMrIfLYKPoxgrvu0BmlZ7uFoX2IVubMaUUgwz0QOzGARA7hYtRMtR0OYTFFNUuEVIACU3HnLD+iBtAjJ+SRewOezdtRaXI6DnMnoTfgp7PsYf6C2/Ty2R89RWLbgH6a0w1+dwTJisKUyMaOfx+qdDNoTarZdOGg9Fk8jMCjhGlPVd14fxp5pi20AamdHWn+qNQ+oMX4bl1rUHG2wt2IdqxNdtnqQMwKqIFT8ILO+nARm2W5T7p+2KbaIssBImHrUfFwWWvVAQiYuZ/n0p+KaUN+Llneq74greC3zecWq+aTM0CleyLVPEyRm16v9RidrExe4/eoGIrKs2XMMV2WGAxYEnvMSfkFFXxDgh73Ad5ETsCiZd3Nil9CulsFr8C7gGnYEbvai9Y/IUz/StdvPAB69CIKd/5SGNnUT9eeTEFWit9G+hVrJ4HEoxK0FCtR52wVoU6bOdSJBA9WN3FvpEheWqVVhU2koMjEOXx
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CS1PR8401MB1192.NAMPRD84.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(39860400002)(376002)(346002)(136003)(396003)(366004)(7696005)(52536014)(966005)(478600001)(64756008)(110136005)(66946007)(55236004)(54906003)(86362001)(6506007)(55016002)(316002)(66556008)(66476007)(8936002)(186003)(83380400001)(8676002)(71200400001)(26005)(53546011)(33656002)(76116006)(9686003)(2906002)(66446008)(4326008)(38100700001)(5660300002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: jsnjsYwTtWY2/vIUbxfeAUzUeT72bF9Er4YBVJfO5s1RgH7wEZzodDjYfpfLpWJ0j30AvFIewVLf16rLvVEPoU+s/e9CyKsFi/wR7XactUN/vEX9CjIfffUxiCFAcyDdWTlbrI/Ybr6lua7sTJuck4xmAHM3GcgcEl7yHLmrdEO1tuNpnbtGuXf/Q+/AHkyI/Cj87EzhHKK19cDfFoBnM0WADeYJwaVPiPczYDKlYE886Po5wlpG5Sfu+Uwb7TNie4WM0x7C0lityUt3/LdtWCXv/bP+4zmqSHwQR+G4zej7CPWANxwNe5wv0n+m1PjPl+VLdZLgH5RYBmVgOcZ3AkU7dab6N067WunDWbW6hvDw7qPtv8LAig+QK/jZp0fIZDZbuqb7lnQdHeBQtIN41pRqVLhceZflOaxms3LhSJnMGHOXN7j6SbjR8GMk7vH1Pjqe72PsMP5H81qpGfv7DHJUo8sBKL++K0YOFeTDz0KjZZXVxrinzv3ofxKh5LcScmweYfMzqCUgdsTXGGiWq1FUauwh9xoN8WEg/ImjP2Pis41L1sD4PpDzNeDsupkUTiCygr0bf1bVYz3E1yB7r07Ce5Xb05RpPNAy66jAVvpDBvZNOrgeVGLQXONfPJVGGFumF4zqjK43x5rrzuWyhNG3QDPU2DnxmTToaetqDBpQoQF48Breh/VottNoQ6KdKvxKkO49Iih72yNJuBWa7BqTJUP5oZhbifuGPCx2qh3jLA2CnBcdtKMiATlC3P3jfFZyWlDnzvWdh1VkUCFOqz45A+x7DfhvdTWpBHmY12tVe6N62skXXdQa2D4wy2r0nG7QL1MJoGZi6UU+FMyZxlcRO44nGi0N1MXE1+WTiYfNzJIsaJxGemv6r/sQKEsR1PUevrIMKYQOeC3kj3kFWqtWxjV5oZ9+HSrc9YM+UzwdjVpI9itckKasF+iRWm5Hi5eOJsxDAhbSffIVGkOe6tTo+Mk8eQfuvEHW74C+pNVoTR4eHf48ZLeOKIaipD1RjMwvVU3IN/x530bbDvPCVIRkGwEw3iIapRgIPcGJnRvuI3aCXLY1WS1EhppT5dyKqUGDHCoYhhVGQ0oQQtF83TsMu3h017WXQ7UjT/WljmWOEFF5nV9jl7O1zcPEto+H8HfRlmRrEScBgsdVQOQ8D2SgH9w+f9BXIYYJHekqyhAtEiu4lu/WnJ7JdxhfEs6Wi8rR88aSs7BfSEVfwLbEvOTta5JEj7CAcCfIYSxzwQpWeMNogYQ5MpYL7kLgklfkm5e0A6JZK1TN8vq0OjZChwWXrXEqNfB4CIq+2lKLNZi1PyJYPB+0KpmIa+fsWgKC
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="us-ascii"
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CS1PR8401MB1192.NAMPRD84.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 44aa9f96-417b-41ab-93bc-08d8f6228ccb
X-MS-Exchange-CrossTenant-originalarrivaltime: 02 Apr 2021 21:59:12.2958 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 105b2061-b669-4b31-92ac-24d304d195dc
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 7a/95s2TcEPPfRyqBj1aapHhAUC+nQlUuZaTxVMJHFfDFaUGX+1LJquxjk3+pdFPL9KrpbEMc+MfiK0WBT4AhQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CS1PR8401MB0853
X-OriginatorOrg: hpe.com
X-Proofpoint-GUID: A2aeV4D94yWXslc0W7_1Kfkq4kKz4s4s
X-Proofpoint-ORIG-GUID: A2aeV4D94yWXslc0W7_1Kfkq4kKz4s4s
Content-Transfer-Encoding: quoted-printable
X-Proofpoint-UnRewURL: 0 URL was un-rewritten
MIME-Version: 1.0
X-HPE-SCL: -1
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.369, 18.0.761 definitions=2021-04-02_15:2021-04-01, 2021-04-02 signatures=0
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 mlxscore=0 clxscore=1011 suspectscore=0 bulkscore=0 mlxlogscore=999 phishscore=0 malwarescore=0 lowpriorityscore=0 priorityscore=1501 spamscore=0 adultscore=0 impostorscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2103310000 definitions=main-2104020144
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/77OX6-wkjuM1QHnEfWtZQXzEW3g>
Subject: Re: [IPsec] draft-xu-ipsecme-esp-in-udp-lb-07
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 02 Apr 2021 21:59:22 -0000

Hi Valery:

Agreed that LB only needs control of the source port to provide entropy. 

Our application is for traversal of highly meshed data centre fabrics. We encapsulate and de-encapsulate at the server using smart NICs and so don't have any impact on RSS or host software (nor improvement over their standard operation). We perform the encapsulation/de-encapsulation after the ESP packet is formed. Since encapsulation occurs after and de-encapsulation occurs before the IPsec stack, IPsec does not see any of the new port assignments so we don't have any issues with the SADB or IKE.

Cheers,

Paul

-----Original Message-----
From: Valery Smyslov [mailto:smyslov.ietf@gmail.com] 
Sent: Thursday, April 1, 2021 11:08 PM
To: 'Tero Kivinen' <kivinen@iki.fi>; Bottorff, Paul <paul.bottorff@hpe.com>
Cc: 'IPsec' <ipsec@ietf.org>; antony.antony@secunet.com
Subject: RE: [IPsec] draft-xu-ipsecme-esp-in-udp-lb-07

Hi Tero,

> For the load balancing I think it is enough for just one of the ports 
> to be different, thus initiator could simply allocate n random source 
> port numbers, and initiate IKE from each of them to responder, and 
> then create SAs for each of them separately, thus allowing load 
> balancing using UDP encapsulation using existing hardware.

RFC 7791 + MOBIKE can be used to clone IKE SA  and move it to a different local IP+port.

Regards,
Valery.

> --
> kivinen@iki.fi
> 
> _______________________________________________
> IPsec mailing list
> IPsec@ietf.org
> INVALID URI REMOVED
> man_listinfo_ipsec&d=DwICAg&c=C5b8zRQO1miGmBeVZ2LFWg&r=CCwOcKkISkWxd8Ymy11M8VW3U6Peq8aJ_DDlgVbQW5E&m=ykseXYzNH5MG1guNwTPMGiGby4o46mBhv92vwoSpb0U&s=nCqbPzmEc1xdTkL0jPmKmNgH252j3dURPVnH8bt4OtE&e=