60 likes | 134 Views
Update on ESP and AH protocols focusing on multicast considerations, anti-replay requirements, SA identification, and protocol fields. Discusses the use of tunnel vs. transport modes and SAD flags for unicast and multicast communications.
E N D
Update on ESP v2 & AH v2 and a Word on 2401bis Steve Kent BBN Technologies
ESP & AH Changes • Revised SA identification text to better accommodate multicast (MSEC WG) • Clarified anti-replay requirements for multicast & multi-sender SAs (MSEC WG) • Move discussion of when to use tunnel vs. transport modes to 2401 bis • Should we remove mandatory algorithm references from AH + ESP?
SA Identification • Unicast: SPI is sufficient, receiver may use protocol (AH/ESP) too, but a purely local decision • Multicast: SHOULD support demuxing based on SPI & destination address and optionally, source address too • SAD flags to cover unicast and multicast: • SPI only • SPI + destination address • SPI + source + destination addresses • But, what about protocol field in multicast case?
Anti-Replay • Transmitter always increments sequence number • Receiver may choose to ignore, locally • Receiver SHOULD tell transmitter to ignore sequence counter wrap-around via IKE negotiation, if the receiver is not going to perform anti-replay check (implies an SAD flag) • Multi-sender SA anti-replay not supported at this time
2401bis • Reconcile with IKEv2 selector capabilities • Relax specs on when to use tunnel vs.transport mode • Add forwarding/routing lookup prior to SPD lookup, for more sophisticated VPN support • Remove mandatory algorithm references?