Re: [IPsec] ESP next payload number [Re: Some thoughts regarging draft-hopps-ipsecme-iptfs-01]
Benjamin Kaduk <kaduk@mit.edu> Mon, 02 December 2019 02:29 UTC
Return-Path: <kaduk@mit.edu>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 59B00120122 for <ipsec@ietfa.amsl.com>; Sun, 1 Dec 2019 18:29:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.299
X-Spam-Level:
X-Spam-Status: No, score=-2.299 tagged_above=-999 required=5 tests=[RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sk-lru0M4oKd for <ipsec@ietfa.amsl.com>; Sun, 1 Dec 2019 18:29:05 -0800 (PST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2417712011F for <ipsec@ietf.org>; Sun, 1 Dec 2019 18:29:04 -0800 (PST)
Received: from mit.edu ([24.16.140.251]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.14.7/8.12.4) with ESMTP id xB22Sxtd024442 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Sun, 1 Dec 2019 21:29:01 -0500
Date: Sun, 01 Dec 2019 18:28:59 -0800
From: Benjamin Kaduk <kaduk@mit.edu>
To: Christian Hopps <chopps@chopps.org>
Cc: Paul Wouters <paul@nohats.ca>, IPsecME WG <ipsec@ietf.org>, Valery Smyslov <smyslov.ietf@gmail.com>
Message-ID: <20191202022859.GE32847@mit.edu>
References: <039e01d5a5f2$ac51d350$04f579f0$@gmail.com> <A8BDEB5B-332E-4767-9EC6-9AF4CFA2E34B@chopps.org> <042301d5a6b6$bc8e9fe0$35abdfa0$@gmail.com> <C6E9B9B8-EE15-4E86-8C39-77BCFF50ADC2@chopps.org> <044701d5a6d0$032d5a90$09880fb0$@gmail.com> <5CAB559D-595E-4503-AC72-31E88B6F53AA@chopps.org> <alpine.LRH.2.21.1912010233510.2378@bofh.nohats.ca> <3F136824-B2BB-429A-BC24-226FC2F9D199@chopps.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <3F136824-B2BB-429A-BC24-226FC2F9D199@chopps.org>
User-Agent: Mutt/1.12.1 (2019-06-15)
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/A_mg6WzbxcEp8DVZMXZ5PqY53lE>
Subject: Re: [IPsec] ESP next payload number [Re: Some thoughts regarging draft-hopps-ipsecme-iptfs-01]
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Dec 2019 02:29:06 -0000
On Sun, Dec 01, 2019 at 03:52:30AM -0500, Christian Hopps wrote: > I think it's important for this discussion to recognize that we have 2 orthogonal issues. > > 1) How does IP-TFS work on the wire with IPsec/ESP - this is where we need to make sure we don't unnecessarily restrict uni-directional use. > > 2) What are the changes to IKEv2 to support IP-TFS - this is where we need to decided if we need the ability to negotiate uni-direction cases, we don't believe we need to do this. I think this is inline with what people are expecting here (i.e., a pair of SAs with IP-TFS enabled or not). > > More inline.. > > > On Dec 1, 2019, at 2:41 AM, Paul Wouters <paul@nohats.ca> wrote: > > > > On Fri, 29 Nov 2019, Christian Hopps wrote: > > > > It seems unwise to protect traffic one way but not the other way. Are > > endusers really able to make the right decision based on their generated > > traffic? If you are that hungry for resources, perhaps this isn't an > > option for you to use? > > There is no traffic to protect in the reverse direction. Consider telemetry where one is simply sending un-acked UDP data using to monitors. I feel like I must be missing something; if there's no traffic in the reverse direction why does it matter if we assign semantics to the reverse SA or not? -Ben
- [IPsec] Some thoughts regarging draft-hopps-ipsec… Valery Smyslov
- [IPsec] IKEv2 IPTFS transform [Re: Some thoughts … Christian Hopps
- Re: [IPsec] IKEv2 IPTFS transform [Re: Some thoug… Valery Smyslov
- [IPsec] ESP next payload number [Re: Some thought… Christian Hopps
- Re: [IPsec] ESP next payload number [Re: Some tho… Valery Smyslov
- Re: [IPsec] IKEv2 IPTFS transform [Re: Some thoug… Christian Hopps
- Re: [IPsec] IKEv2 IPTFS transform [Re: Some thoug… Valery Smyslov
- Re: [IPsec] ESP next payload number [Re: Some tho… Christian Hopps
- Re: [IPsec] ESP next payload number [Re: Some tho… Valery Smyslov
- Re: [IPsec] ESP next payload number [Re: Some tho… Christian Hopps
- Re: [IPsec] ESP next payload number [Re: Some tho… Michael Richardson
- Re: [IPsec] ESP next payload number [Re: Some tho… Michael Richardson
- Re: [IPsec] ESP next payload number [Re: Some tho… Christian Hopps
- Re: [IPsec] IKEv2 IPTFS transform [Re: Some thoug… Paul Wouters
- Re: [IPsec] ESP next payload number [Re: Some tho… Paul Wouters
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Paul Wouters
- Re: [IPsec] ESP next payload number [Re: Some tho… Christian Hopps
- Re: [IPsec] IKEv2 IPTFS transform [Re: Some thoug… Christian Hopps
- Re: [IPsec] ESP next payload number [Re: Some tho… Benjamin Kaduk
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Steffen Klassert
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Valery Smyslov
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Steffen Klassert
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Valery Smyslov
- Re: [IPsec] ESP next payload number [Re: Some tho… Christian Hopps
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Christian Hopps
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Steffen Klassert
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Christian Hopps
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Steffen Klassert
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Valery Smyslov
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Christian Hopps
- Re: [IPsec] Some thoughts regarging draft-hopps-i… Christian Hopps