I'd like to pick up on this thread https://mailarchive.ietf.org/arch/browse/ipsec/?gbt=1&index=_a7dgrxWgS_hqhUQaHBNlIoJbbA which was discussing what to do when initial exchanges crossed.
I've several reasons for revisiting it: - while statistically rare, it is not random; rather it is highly predictable - after any power fail or phy restore, when things are expected to come up ASAP - in a world where 3 or more exchanges are required to authenticate the IKE SA; I think there's value in not throwing that effort away My suggestion is for the responder, during IKE_AUTH, to complete authentication of the IKE SA but then reject the Child SA with TEMPORARY_FAILURE - i.e., back off for a moment. The initiator can then, after some jitter, and assuming the Child SA hasn't established, initiate a CREATE_CHILD_SA for the failed Child SA using the still established IKE SA. Andrew _______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
