Re: [I2nsf] [IPsec] Review of draft-ietf-i2nsf-sdn-ipsec-flow-protection-03 (Section 1)

2018-11-27 Thread Yoav Nir
A couple of remarks (with no hats) If we’re bikeshedding the names, I think the difference is that in one case the two NSFs generate traffic keys between themselves, and in the other it is the controller that generates the keys for them. So how about “distributed keying” vs “centralized keying

Re: [I2nsf] [IPsec] Review of draft-ietf-i2nsf-sdn-ipsec-flow-protection-03 (Section 1)

2018-11-27 Thread Gabriel Lopez
Hi Paul, > El 27 nov 2018, a las 14:34, Paul Wouters escribió: > > On Tue, 27 Nov 2018, Gabriel Lopez wrote: > >> Hi Paul, all >> Please find attached some answers to your comments. Let’s go section by >> section, it will be easier to follow the discussion. >> >> El 18 nov 2018, a las 7:

Re: [I2nsf] Review of draft-ietf-i2nsf-sdn-ipsec-flow-protection-03 (Section 3)

2018-11-27 Thread Rafa Marin-Lopez
Hi Paul: > Section 3: > > It requires information about the > required authentication method (i.e. preshared keys), DH groups, > modes and algorithms for IKE SA negotiation, etc. > > In the IKE world, we really try to not recommend preshared keys, because > these keys mostly based on

Re: [I2nsf] [IPsec] Review of draft-ietf-i2nsf-sdn-ipsec-flow-protection-03 (Section 1)

2018-11-27 Thread Paul Wouters
On Tue, 27 Nov 2018, Gabriel Lopez wrote: Hi Paul, all Please find attached some answers to your comments. Let’s go section by section, it will be easier to follow the discussion. El 18 nov 2018, a las 7:52, Paul Wouters escribió: General comments: I'd like to see "Case 1" and "Case

Re: [I2nsf] [IPsec] Review of draft-ietf-i2nsf-sdn-ipsec-flow-protection-03 (Section 1)

2018-11-27 Thread Gabriel Lopez
Hi Paul, all Please find attached some answers to your comments. Let’s go section by section, it will be easier to follow the discussion. > El 18 nov 2018, a las 7:52, Paul Wouters escribió: > > > > > > General comments: > I'd like to see "Case 1" and "Case 2" replaced with more descript