Re: [IPsec] Proposed work item: IKE/IPsec high availability and load sharing

Daniel Migault <mglt.ietf@gmail.com> Mon, 07 December 2009 15:31 UTC

Return-Path: <mglt.ietf@gmail.com>
X-Original-To: ipsec@core3.amsl.com
Delivered-To: ipsec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id BFA883A6A69 for <ipsec@core3.amsl.com>; Mon, 7 Dec 2009 07:31:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YJmY-NhXQPcx for <ipsec@core3.amsl.com>; Mon, 7 Dec 2009 07:31:54 -0800 (PST)
Received: from mail-bw0-f223.google.com (mail-bw0-f223.google.com [209.85.218.223]) by core3.amsl.com (Postfix) with ESMTP id 7CB223A6A63 for <ipsec@ietf.org>; Mon, 7 Dec 2009 07:31:53 -0800 (PST)
Received: by bwz23 with SMTP id 23so3691017bwz.29 for <ipsec@ietf.org>; Mon, 07 Dec 2009 07:31:40 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:message-id:subject:from:to:cc:content-type; bh=lqlAurrr7QdFpfN9q2iltkgzMZCoa852qeVBcXRs+Mg=; b=nqWv/QLJPVGFR5eeL+NzCA56bVuITX/+hwoRF7J97O93wS4KhKEil+7djMDPGzkpzA z7P9nNUkIBLh9zXEzRexW+u9a/U/3RgGeMjjid8wlsqyiS4qZlNjAqpm4ODtw/ZNNiiP j3R7+zIwgez5bRGPaOf1BfDnMvimQfap0dCZI=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=m9KhwxP9/4RUYkbc4rxkk8znfogovqWXCPKDuQhSfFQDfPOSYr0t4ezzzg5C5t7LD1 eWNb2dBNDtcHw60SLiyiD+cmLX0+98X5MsimKl3qjnQ395tku/uAL3LV0HiUO9MEa0Oi XzPyC4yrLdhvIG2D4UON6QUTFgdvve/GRJQCo=
MIME-Version: 1.0
Received: by 10.103.126.33 with SMTP id d33mr2238073mun.109.1260199899987; Mon, 07 Dec 2009 07:31:39 -0800 (PST)
In-Reply-To: <4B187F5C.6050102@sandelman.ca>
References: <7F9A6D26EB51614FBF9F81C0DA4CFEC801BDF88E04F1@il-ex01.ad.checkpoint.com> <4B187F5C.6050102@sandelman.ca>
Date: Mon, 07 Dec 2009 16:31:39 +0100
Message-ID: <51eafbcb0912070731w2c13d799va76a43f6b3bb6aa5@mail.gmail.com>
From: Daniel Migault <mglt.ietf@gmail.com>
To: Michael Richardson <mcr@sandelman.ca>
Content-Type: multipart/alternative; boundary="0016e65b3ffc627d86047a252743"
Cc: ipsec@ietf.org
Subject: Re: [IPsec] Proposed work item: IKE/IPsec high availability and load sharing
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipsec>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Dec 2009 15:31:54 -0000

I will also review this document.
Regards,
Daniel

On Fri, Dec 4, 2009 at 4:17 AM, Michael Richardson <mcr@sandelman.ca> wrote:

> Yaron Sheffer wrote:
>
>> This work item will define the problem statement and requirements for a
>> solution that allows interoperable HA/LS device groups. Mixed-vendor
>> clusters are specifically out of scope; but single-vendor clusters should be
>> fully interoperable with other vendors’ devices or clusters. The main
>> challenge is to overcome the strict use of sequence numbers in both IPsec
>> and IKE, in HA and LS scenarios. Following the Hiroshima discussion, the WI
>> is initially focused on defining the problem, rather than a particular
>> solution.
>>
>>
>> Proposed starting point:
>> http://tools.ietf.org/id/draft-nir-ipsecme-ipsecha-00.txt.
>>
>>
>> Please reply to the list:
>>
>
> It is interesting work, and may well be valuable.
> It is not a priority to me, and I would not have time to work on it.
> I might read a WG FC, and I might respond to threads, if I came across
> them.
>
>
>
>
> _______________________________________________
> IPsec mailing list
> IPsec@ietf.org
> https://www.ietf.org/mailman/listinfo/ipsec
>



-- 
Daniel Migault
Orange Labs -- Security
+33 6 70 72 69 58