Re: [IPsec] I-D Action: draft-ietf-ipsecme-ike-tcp-01.txt

2012-12-11 Thread Valery Smyslov
Hi, I'm a bit uncomfortable with the requirement that IKE peer MUST advertise NAT device port if it is reachable and MUST NOT if it isn't. I think, that IKE Initiator in most cases cannot reliably determine whether it is reachable or not. For example, even if you manually configured port

Re: [IPsec] New draft on IKE Diffie-Hellman checks

2012-12-11 Thread Dan Harkins
Hello, I have a few comments. - The Introduction says that It turns out using EC groups in some scenarios require...additional tests. This document defines these tests. Well the memo is defining more than EC. I think the Intro should introduce us to the why, which is

[IPsec] Comments on proposed draft-ietf-ipsecme-ad-vpn-problem-02

2012-12-11 Thread Brian Weis
Hi Steve Vishwas, Here are a couple of comments on the proposed -02 sent a few days ago. Requirement 1 says gateways and endpoints MUST minimize configuration changes when a new gateway or endpoint is added, removed or changed. While I certainly agree with the sentiment behind the

Re: [IPsec] New draft on IKE Diffie-Hellman checks

2012-12-11 Thread Dan Harkins
I made a mistake below. Thanks to Dan Brown for pointing it out. On Tue, December 11, 2012 10:06 am, Dan Harkins wrote: [snip] - I think it should be mentioned that elliptic curve groups have a co-factor, h, and if h 1 that a further check is also required, namely, if the x-