Hi Tero,

> For the load balancing I think it is enough for just one of the ports
> to be different, thus initiator could simply allocate n random source
> port numbers, and initiate IKE from each of them to responder, and
> then create SAs for each of them separately, thus allowing load
> balancing using UDP encapsulation using existing hardware.

RFC 7791 + MOBIKE can be used to clone IKE SA  and move 
it to a different local IP+port.

Regards,
Valery.

> --
> kivi...@iki.fi
> 
> _______________________________________________
> IPsec mailing list
> IPsec@ietf.org
> https://www.ietf.org/mailman/listinfo/ipsec

_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to