Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-26 Thread Michael Richardson
<#part sign=pgpmime> Actually, in my haste, I skipped a possible step: step1, H1 tells A that H2 is closer: AB \ / \. / \

Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-26 Thread Michael Richardson
> "Yoav" == Yoav Nir writes: >> You didn't take my comments too far; I think you realized that I was in >> fact saying two things: >> >> 1) when traffic is redirected, MUST it be redirected directly to the >> real endpoint? (There might be issues of in-band double NAT th

Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-26 Thread Yoav Nir
On Mar 26, 2012, at 10:47 AM, Michael Richardson wrote: > >> "Yaron" == Yaron Sheffer writes: >Yaron> I don't want to speak for MCR, but I think you are taking his >Yaron> question too far towards the implementation aspects. What I >Yaron> read in the question is, do we allow fo

Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-26 Thread Michael Richardson
> "Yaron" == Yaron Sheffer writes: Yaron> I don't want to speak for MCR, but I think you are taking his Yaron> question too far towards the implementation aspects. What I Yaron> read in the question is, do we allow for a situation where Yaron> (by policy and/or because of limi

Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-26 Thread Michael Richardson
{fat fingers let previous email got away too soon, ignore} > "Stephen" == Stephen Hanna writes: Stephen> I think that Michael is asking an important question. There Stephen> are many ways to solve the P2P VPN problem. One way is to Stephen> have satellites with little configurati

Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-26 Thread Michael Richardson
> "Stephen" == Stephen Hanna writes: Stephen> I think that Michael is asking an important question. There Stephen> are many ways to solve the P2P VPN problem. One way is to Stephen> have satellites with little configuration that connect to Stephen> core gateways with lots of d

Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-21 Thread Stephen Hanna
c: Stephen Hanna; IPsecme WG > Subject: Re: [IPsec] [ipsecme] #214: Should gateways figure things out > completely or just punt endpoints to a closer gateway? > > Hi Steve, Yoav, > > I don't want to speak for MCR, but I think you are taking his question > too far tow

Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-21 Thread Yaron Sheffer
]*On Behalf Of*Vishwas Manral *Sent:*Wednesday, March 21, 2012 3:18 PM *To:*Stephen Hanna *Cc:*IPsecme WG *Subject:*Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway? Hi Steve, This is unclear to me. Isn't it routing that we sen

Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-21 Thread Yoav Nir
to:ipsec-boun...@ietf.org] On Behalf Of Vishwas Manral Sent: Wednesday, March 21, 2012 3:18 PM To: Stephen Hanna Cc: IPsecme WG Subject: Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway? Hi Steve, This is unclear to me. Isn'

Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-21 Thread Stephen Hanna
Steve From: ipsec-boun...@ietf.org [mailto:ipsec-boun...@ietf.org] On Behalf Of Vishwas Manral Sent: Wednesday, March 21, 2012 3:18 PM To: Stephen Hanna Cc: IPsecme WG Subject: Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway? Hi S

Re: [IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-21 Thread Vishwas Manral
Hi Steve, This is unclear to me. Isn't it routing that we send a packet across to a closer gateway/ router? What does everything mean in the question below? If we are talking about say security and routing, I think that is true. The "logical" gateway (could be multiple interactions and devices) s

[IPsec] [ipsecme] #214: Should gateways figure things out completely or just punt endpoints to a closer gateway?

2012-03-20 Thread Stephen Hanna
Please comment on Suggested Resolution. Note that Yaron has already supplied his comment below. Steve -Original Message- From: ipsecme issue tracker [mailto:t...@tools.ietf.org] Sent: Tuesday, March 20, 2012 6:59 PM To: yaronf.i...@gmail.com; draft-ietf-ipsecme-p2p-vpn-prob...@tools.ietf