Re: [IPsec] Discussion of draft-pwouters-ipsecme-multi-sa-performance

2022-10-20 Thread Valery Smyslov
Hi Paul, > On Wed, 19 Oct 2022, Valery Smyslov wrote: > > >> Requesting to install 1 million Child SA's until the remote server falls > >> over. > >> Perhaps less extremely, to contain the number of resources a sysadmin > >> allocates to a specific "multi CPU" tunnel. > > > > I still fail to und

[IPsec] Lars Eggert's Discuss on draft-ietf-ipsecme-mib-iptfs-09: (with DISCUSS and COMMENT)

2022-10-20 Thread Lars Eggert via Datatracker
Lars Eggert has entered the following ballot position for draft-ietf-ipsecme-mib-iptfs-09: Discuss When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to http

Re: [IPsec] [Gen-art] Genart last call review of draft-ietf-ipsecme-mib-iptfs-04

2022-10-20 Thread Lars Eggert
Joel, thank you for your review. I have entered a Discuss ballot for this document based on my own review. Lars > On 2022-9-22, at 1:50, Joel Halpern via Datatracker wrote: > > Reviewer: Joel Halpern > Review result: Almost Ready > > I am the assigned Gen-ART reviewer for this draft. The Gen

[IPsec] Fwd: New Version Notification for draft-xu-risav-02.txt

2022-10-20 Thread Ben Schwartz
Hello IPSEC, We've just put out an extensively revised version of our RISAV proposal (the I stands for IPsec). We'd like to start getting feedback from the IPsec experts. We're also hoping to present this idea and solicit feedback at IETF 115. This is an early stage proposal with a lot of open

Re: [IPsec] Fwd: New Version Notification for draft-xu-risav-02.txt

2022-10-20 Thread Erik Kline
I don't understand how "transport mode" can work for non-originated packets; for IPv6, inserting random headers along the path would violate 8200. On Thu, Oct 20, 2022 at 7:23 AM Ben Schwartz wrote: > Hello IPSEC, > > We've just put out an extensively revised version of our RISAV proposal > (the

Re: [IPsec] Fwd: New Version Notification for draft-xu-risav-02.txt

2022-10-20 Thread Ben Schwartz
The RISAV-AH header is inserted as the packet exits the source AS, and removed as the packet enters the destination AS. Thus, it has the same net effect as an ESP tunnel, and IMHO should not be viewed as a violation of RFC 8200. Where this gets interesting is ICMP responses from intermediary rout

[IPsec] I-D Action: draft-ietf-ipsecme-mib-iptfs-10.txt

2022-10-20 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the IP Security Maintenance and Extensions WG of the IETF. Title : Definitions of Managed Objects for IP Traffic Flow Security Authors : Don Fedyk

[IPsec] Zaheduzzaman Sarker's No Objection on draft-ietf-ipsecme-mib-iptfs-10: (with COMMENT)

2022-10-20 Thread Zaheduzzaman Sarker via Datatracker
Zaheduzzaman Sarker has entered the following ballot position for draft-ietf-ipsecme-mib-iptfs-10: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please r

Re: [IPsec] Genart last call review of draft-ietf-ipsecme-ikev2-multiple-ke-07

2022-10-20 Thread CJ Tjhai
Hi Russ, Many thanks for the review of our document. Please see our comments inline below. The updated version of the draft is available here: https://github.com/post-quantum/ietf-pq-ikev2/blob/master/draft-ietf-ipsecme-ikev2-multiple-ke-00.xml Best regards, CJ and Valery On Fri, 14 Oct 2022 at