I'd like to pick up on this thread
  
https://mailarchive.ietf.org/arch/browse/ipsec/?gbt=1&index=_a7dgrxWgS_hqhUQaHBNlIoJbbA
which was discussing what to do when initial exchanges crossed.

I've several reasons for revisiting it:

- while statistically rare, it is not random; rather it is highly
predictable - after any power fail or phy restore, when things are
expected to come up ASAP
- in a world where 3 or more exchanges are required to authenticate
the IKE SA; I think there's value in not throwing that effort away

My suggestion is for the responder, during IKE_AUTH, to complete
authentication of the IKE SA but then reject the Child SA with
TEMPORARY_FAILURE - i.e., back off for a moment.
The initiator can then, after some jitter, and assuming the Child SA
hasn't established, initiate a CREATE_CHILD_SA for the failed Child SA
using the still established IKE SA.

Andrew

_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to