60 likes | 131 Views
Update on ESP v2 & AH v2 and a Word on 2401bis. Steve Kent BBN Technologies. ESP & AH Changes. Revised SA identification text to better accommodate multicast (MSEC WG) Clarified anti-replay requirements for multicast & multi-sender SAs (MSEC WG)
E N D
Update on ESP v2 & AH v2 and a Word on 2401bis Steve Kent BBN Technologies
ESP & AH Changes • Revised SA identification text to better accommodate multicast (MSEC WG) • Clarified anti-replay requirements for multicast & multi-sender SAs (MSEC WG) • Move discussion of when to use tunnel vs. transport modes to 2401 bis • Should we remove mandatory algorithm references from AH + ESP?
SA Identification • Unicast: SPI is sufficient, receiver may use protocol (AH/ESP) too, but a purely local decision • Multicast: SHOULD support demuxing based on SPI & destination address and optionally, source address too • SAD flags to cover unicast and multicast: • SPI only • SPI + destination address • SPI + source + destination addresses • But, what about protocol field in multicast case?
Anti-Replay • Transmitter always increments sequence number • Receiver may choose to ignore, locally • Receiver SHOULD tell transmitter to ignore sequence counter wrap-around via IKE negotiation, if the receiver is not going to perform anti-replay check (implies an SAD flag) • Multi-sender SA anti-replay not supported at this time
2401bis • Reconcile with IKEv2 selector capabilities • Relax specs on when to use tunnel vs.transport mode • Add forwarding/routing lookup prior to SPD lookup, for more sophisticated VPN support • Remove mandatory algorithm references?