Re: IKEv2: prepending four octets

Francis Dupont <Francis.Dupont@enst-bretagne.fr> Tue, 25 March 2003 20:07 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA29415 for <ipsec-archive@lists.ietf.org>; Tue, 25 Mar 2003 15:07:39 -0500 (EST)
Received: by lists.tislabs.com (8.9.1/8.9.1) id MAA10942 Tue, 25 Mar 2003 12:56:21 -0500 (EST)
Message-Id: <200303251800.h2PI0Hof078292@givry.rennes.enst-bretagne.fr>
From: Francis Dupont <Francis.Dupont@enst-bretagne.fr>
To: Yoav Nir <ynir@CheckPoint.com>
cc: 'Ravi' <ravivsn@roc.co.in>, 'Tero Kivinen' <kivinen@ssh.fi>, ipsec@lists.tislabs.com
Subject: Re: IKEv2: prepending four octets
In-reply-to: Your message of Tue, 25 Mar 2003 09:44:47 +0200. <001201c2f2a2$698ae810$292e1dc2@YnirNew>
Date: Tue, 25 Mar 2003 19:00:17 +0100
X-Virus-Scanned: by amavisd-milter (http://amavis.org/) at enst-bretagne.fr
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

 In your previous mail you wrote:

   I think that we should at least agree that a peer that only works with port
   4500 such as Ravi describes should interoperate with all IKEv2
   implementations.
   
=> I agree.

   IOW an IKEv2 implementation must not assume that peers start the
   negotiations on port 500.

=> I agree.

   Coding a Remote Access client like that is
   acceptable, since clients always initiate the first IKE negotiation.
   Gateways may initiate the negotiation on port 4500 when working with IKEv2
   peers (in fact, this could be a recommendation at the SHOULD level), but
   they SHOULD also listen on port 500.
   
=> I believe we should give at least a MAY to initiate over 500 and 4500,
perhaps with a SHOULD for port 4500 if one knows there is a NAT and a SHOULD
for port 500 if one knows there is no NAT. In fact, this is more in the
scope of a BCP. About listening, I am in favor of a MUST for both 500
and 4500.

Regards

Francis.Dupont@enst-bretagne.fr