Re: NAT Traversal

Bill Sommerfeld <sommerfeld@east.sun.com> Wed, 06 March 2002 22:07 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g26M7r824242; Wed, 6 Mar 2002 14:07:53 -0800 (PST)
Received: by lists.tislabs.com (8.9.1/8.9.1) id QAA17558 Wed, 6 Mar 2002 16:28:09 -0500 (EST)
Message-Id: <200203062138.g26LchUZ013762@ack.east.sun.com>
From: Bill Sommerfeld <sommerfeld@east.sun.com>
To: "Chinna N.R. Pellacuru" <pcn@cisco.com>
cc: Bill Sommerfeld <sommerfeld@east.sun.com>, Paul Koning <pkoning@equallogic.com>, ipsec@lists.tislabs.com
Subject: Re: NAT Traversal
In-Reply-To: Your message of "Wed, 06 Mar 2002 13:24:26 PST." <Pine.GSO.4.33.0203061254550.14106-100000@cypher.cisco.com>
Reply-to: sommerfeld@east.sun.com
Date: Wed, 06 Mar 2002 16:38:43 -0500
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

Chinna,

Please see also:

   The receiver-orientation of the Security Association implies that, in
   the case of unicast traffic, the destination system will normally
   select the SPI value.  By having the destination select the SPI
   value, there is no potential for manually configured Security
   Associations to conflict with automatically configured (e.g., via a
   key management protocol) Security Associations or for Security
   Associations from multiple sources to conflict with each other. 

This means that *IN PRACTICE*, the "REQUIRED" verbiage you cite means
very little.

Moreover, the author of 2401 has stated in public on several occasions
without objection that the "REQUIRED" bits will be weakened in a 2401
followon.

> In any case, I think you bring up another point. Probably you in your
> implementation (probably being an "endpoint" IPsec implementation), will
> only deal with a maximum of a couple of IPsec SAs at any time. 

Please keep ad-hominem attacks off the list.

The Solaris IPsec implementation handles quite a few more SAs than
that.


						- Bill