[v6ops] AERO and enterprise mobile VPN

"Templin, Fred L" <Fred.L.Templin@boeing.com> Mon, 02 November 2015 20:56 UTC

Return-Path: <Fred.L.Templin@boeing.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 92F751B3884 for <v6ops@ietfa.amsl.com>; Mon, 2 Nov 2015 12:56:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 43BFr8c01ko1 for <v6ops@ietfa.amsl.com>; Mon, 2 Nov 2015 12:56:09 -0800 (PST)
Received: from stl-mbsout-01.boeing.com (stl-mbsout-01.boeing.com [130.76.96.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F001C1B3872 for <v6ops@ietf.org>; Mon, 2 Nov 2015 12:56:08 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by stl-mbsout-01.boeing.com (8.14.4/8.14.4/DOWNSTREAM_MBSOUT) with SMTP id tA2Ku7l7028277; Mon, 2 Nov 2015 14:56:07 -0600
Received: from XCH-BLV-105.nw.nos.boeing.com (xch-blv-105.nw.nos.boeing.com [130.247.25.121]) by stl-mbsout-01.boeing.com (8.14.4/8.14.4/UPSTREAM_MBSOUT) with ESMTP id tA2Ku4Br028246 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=OK) for <v6ops@ietf.org>; Mon, 2 Nov 2015 14:56:04 -0600
Received: from XCH-BLV-504.nw.nos.boeing.com ([169.254.4.14]) by XCH-BLV-105.nw.nos.boeing.com ([169.254.5.143]) with mapi id 14.03.0235.001; Mon, 2 Nov 2015 12:56:03 -0800
From: "Templin, Fred L" <Fred.L.Templin@boeing.com>
To: "v6ops@ietf.org" <v6ops@ietf.org>
Thread-Topic: AERO and enterprise mobile VPN
Thread-Index: AdEVsNVlYEbNlbDZSvuSOqMlG+WkFw==
Date: Mon, 02 Nov 2015 20:56:03 +0000
Message-ID: <2134F8430051B64F815C691A62D9831832F37C9F@XCH-BLV-504.nw.nos.boeing.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [130.247.104.6]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-TM-AS-MML: disable
Archived-At: <http://mailarchive.ietf.org/arch/msg/v6ops/tmriDcXprX4L6VD0WiS5d0kcFeg>
Subject: [v6ops] AERO and enterprise mobile VPN
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Nov 2015 20:56:10 -0000

Hello,

Enterprise mobile device users need a way to get back into the enterprise via
the Internet when they are coming in from some form of off-campus access
link. For this, mobile devices are more and more beginning to use VPN clients
that can establish a secure tunnel via an enterprise border security gateway.
But, a mobile VPN client that uses AERO can receive a prefix delegation from
the enterprise that it can retain and use wherever it happens to move to.

AERO can be used for maintaining a mobile VPN service for enterprise mobile
devices. The service can be built into the enterprise network, and the client
functions can be integrated with common VPN clients such as OpenVPN. This
would give end systems a mobile multi-addressing capability that does not
require renumbering even as the end system moves between on- and off-
campus access links.

IMHO, this is a compelling use case as enterprise networks come in a vast
array of shapes and sizes. Comments welcome.

Thanks - Fred
fred.l.templin@boeing.com