Re: [IPsec] draft-nir-ipsecme-puzzles-00 comments

2014-07-15 Thread Valery Smyslov
I think doing this would cause clients to calculate the puzzle solution, when in fact they don’t have to, and sending back the COOKIE would be enough. What I envision is for the IKE gateway to measure its load (probably based on amount of half-open IKE SAs). As long as the load level is low, th

Re: [IPsec] draft-nir-ipsecme-puzzles-00 comments

2014-07-15 Thread Yoav Nir
I think doing this would cause clients to calculate the puzzle solution, when in fact they don’t have to, and sending back the COOKIE would be enough. What I envision is for the IKE gateway to measure its load (probably based on amount of half-open IKE SAs). As long as the load level is low, the

[IPsec] draft-nir-ipsecme-puzzles-00 comments

2014-07-10 Thread Valery Smyslov
Hi Yoav, did you consider the following initial exchange: Initiator Responder --- HDR(A,0), SAi1, KEi, Ni --> <-- HDR(A,0), N(COOKIE), N(PUZZLE) (supported i