Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication

2009-11-16 Thread Frederic Detienne
> Thanks, > -Amjad > > -Original Message- > From: Murthy N Srinivas-B22237 [mailto:b22...@freescale.com] > Sent: Thursday, November 12, 2009 6:35 PM > To: Amjad Inamdar (amjads); Tero Kivinen; Yoav Nir > Cc: ipsec@ietf.org > Subject: RE: [IPsec] Clarification o

Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication

2009-11-14 Thread Murthy N Srinivas-B22237
@cisco.com] Sent: Friday, November 13, 2009 12:31 PM To: Murthy N Srinivas-B22237; Tero Kivinen; Yoav Nir Cc: ipsec@ietf.org Subject: RE: [IPsec] Clarification on identities involved in IKEv2EAPauthentication Hi Murthy, IKEv2 gatway even when acting as a pass-through would need the authent

Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication

2009-11-12 Thread Amjad Inamdar (amjads)
Nir Cc: ipsec@ietf.org Subject: RE: [IPsec] Clarification on identities involved in IKEv2EAPauthentication Amjad, If the Authenticator includes the AAA server implementation,it should no the EAP identity to enforce policies.If AAA server is separate,we can add an attribute to AAA server for this

Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication

2009-11-12 Thread Murthy N Srinivas-B22237
[mailto:ipsec-boun...@ietf.org] On Behalf Of Tero Kivinen Sent: Thursday, November 12, 2009 5:01 AM To: Yoav Nir Cc: ipsec@ietf.org; Amjad Inamdar (amjads) Subject: Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication Yoav Nir writes: > Since the gateway acts as a pass-through,

Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication

2009-11-12 Thread Murthy N Srinivas-B22237
Kivinen Sent: Thursday, November 12, 2009 5:01 AM To: Yoav Nir Cc: ipsec@ietf.org; Amjad Inamdar (amjads) Subject: Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication Yoav Nir writes: > Since the gateway acts as a pass-through, the requirement here is more > for the

Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication

2009-11-12 Thread Amjad Inamdar (amjads)
] On Behalf Of Tero Kivinen Sent: Thursday, November 12, 2009 5:01 AM To: Yoav Nir Cc: ipsec@ietf.org; Amjad Inamdar (amjads) Subject: Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication Yoav Nir writes: > Since the gateway acts as a pass-through, the requirement here is m

Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication

2009-11-12 Thread Yoav Nir
On Nov 12, 2009, at 5:34 AM, Raj Singh wrote: > The selection of AAA server will be based on IDi then EAP will happen. > The gateway will get EAP authenticated ID from the AAA server. > If EAP identity is different from IDi and no policy is found for EAP identity. > The gateway should initiate de

Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication

2009-11-11 Thread Raj Singh
The selection of AAA server will be based on IDi then EAP will happen. The gateway will get EAP authenticated ID from the AAA server. If EAP identity is different from IDi and no policy is found for EAP identity. The gateway should initiate deletion of the SA. Also, if policy is found based on EAP

Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication

2009-11-11 Thread Tero Kivinen
Yoav Nir writes: > Since the gateway acts as a pass-through, the requirement here is > more for the client, which is typically more integrated. The client > should be prepared to give an identity hint both in IKE and later in > the EAP session. And in that case the identities should really be same

Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication

2009-11-11 Thread Yoav Nir
November 11, 2009 7:23 PM > To: Srinivasu S R S Dhulipala (srinid) > Cc: Amjad Inamdar (amjads); ipsec@ietf.org > Subject: Re: [IPsec] Clarification on identities involved in > IKEv2EAPauthentication > > > On Nov 11, 2009, at 3:39 PM, Srinivasu S R S Dhulipala (srinid) wrote: >

Re: [IPsec] Clarification on identities involved in IKEv2EAPauthentication

2009-11-11 Thread Srinivasu S R S Dhulipala (srinid)
Hi Yoav, Thanks for the quick response. Please see inline. -Original Message- From: Yoav Nir [mailto:y...@checkpoint.com] Sent: Wednesday, November 11, 2009 7:23 PM To: Srinivasu S R S Dhulipala (srinid) Cc: Amjad Inamdar (amjads); ipsec@ietf.org Subject: Re: [IPsec] Clarification on