On Wed, 2 Sept 2026 at 14:04, Wang Xi <[email protected]> wrote:

> Regarding Andrew’s suggestion of manipulating the packet flow at the kernel 
> level: correct me if I am wrong, but isn't this mechanism also strictly 
> dependent on the explicit generation of the Child SA SPIs?

No one has suggested manipulating packets at the kernel level.
(MIchael has suggested adding a delay when sending IKE packets as part
of the IKE negotiation, and to use nonce to decide a "winner"; but
that is very different).

> I would suggest an Application-Layer Fast Refusal at that exact junction 
> instead: Once the IKE_AUTH exchange begins and the responder aligns the 
> peer’s identity (successfully detecting a genuine collision and generating 
> the corresponding SPIs), the losing party should immediately reply with a 
> fast-fail Notify Payload (e.g., COLLISION_ABORT) and tear down its local 
> half-open state instantly.

Where COLLISION_ABORT is a new error notification.  So would tear down
the IKE SA.
Remember, the original initiator, can't "respond", it needs to
immediately initiate a new exchange after the IKE_AUTH response
arrives.  At that point it might as well initiate a delete.

_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to