On Wed, 2 Sept 2026 at 14:04, Wang Xi <[email protected]> wrote: > Regarding Andrew’s suggestion of manipulating the packet flow at the kernel > level: correct me if I am wrong, but isn't this mechanism also strictly > dependent on the explicit generation of the Child SA SPIs?
No one has suggested manipulating packets at the kernel level. (MIchael has suggested adding a delay when sending IKE packets as part of the IKE negotiation, and to use nonce to decide a "winner"; but that is very different). > I would suggest an Application-Layer Fast Refusal at that exact junction > instead: Once the IKE_AUTH exchange begins and the responder aligns the > peer’s identity (successfully detecting a genuine collision and generating > the corresponding SPIs), the losing party should immediately reply with a > fast-fail Notify Payload (e.g., COLLISION_ABORT) and tear down its local > half-open state instantly. Where COLLISION_ABORT is a new error notification. So would tear down the IKE SA. Remember, the original initiator, can't "respond", it needs to immediately initiate a new exchange after the IKE_AUTH response arrives. At that point it might as well initiate a delete. _______________________________________________ IPsec mailing list -- [email protected] To unsubscribe send an email to [email protected]
