Re: [IPsec] FW: New Version Notification for draft-liu-ipsecme-ikev2-rekey-redundant-sas-00.txt

2021-11-24 Thread Tero Kivinen
Paul Wouters writes: > So why not, instead of a random process, exchange the maximum Child SA > lifetime accepted before rekey? If the numbers are identical, prefer the > current exchange initiator. > > That way, it is deterministic and both endpoints inform the other end > when (plus or minus som

Re: [IPsec] FW: New Version Notification for draft-liu-ipsecme-ikev2-rekey-redundant-sas-00.txt

2021-11-24 Thread Valery Smyslov
Hi Harold, I failed to understand one thing. The situation you are trying to avoid in most cases happens if peers are configured with equal SA lifetime. Why you don't just configure your gateways with different lifetimes? It seems to me that in scenarios you describe you have a total control over