IETF RFC 6290 PDF

IETF RFC 6290 PDF

Name:
IETF RFC 6290 PDF

Published Date:
06/01/2011

Status:
[ Active ]

Description:

A Quick Crash Detection Method for the Internet Key Exchange Protocol (IKE)

Publisher:
Internet Engineering Task Force

Document status:
Active

Format:
Electronic (PDF)

Delivery time:
10 minutes

Delivery time (for Russian version):
200 business days

SKU:

Choose Document Language:
$11.1
Need Help?

Introduction

IKEv2, as described in [RFC5996] and its predecessor RFC 4306, has a method for recovering from a reboot of one peer. As long as traffic flows in both directions, the rebooted peer should re-establish the tunnels immediately. However, in many cases, the rebooted peer is a VPN gateway that protects only servers, so all traffic is inbound. In other cases, the non-rebooted peer has a dynamic IP address, so the rebooted peer cannot initiate IKE because its current IP address is unknown. In such cases, the rebooted peer will not be able to re-establish the tunnels. Section 2 describes how recovery works under RFC 5996, and explains why it may take several minutes.

The method proposed here is to send an octet string, called a "QCD token", in the IKE_AUTH exchange that establishes the tunnel. That token can be stored on the peer as part of the IKE SA. After a reboot, the rebooted implementation can re-generate the token and send it to the peer, so as to delete the IKE SA. Deleting the IKE SA results in a quick establishment of new IPsec tunnels. This is described in Section 3.

Conventions Used in This Document

The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].

The term "token" refers to an octet string that an implementation can generate using only the properties of a protected IKE message (such as IKE Security Parameter Indexes (SPIs)) as input. A conforming implementation MUST be able to generate the same token from the same input even after rebooting.

The term "token maker" refers to an implementation that generates a token and sends it to the peer as specified in this document.

The term "token taker" refers to an implementation that stores such a token or a digest thereof, in order to verify that a new token it receives is identical to the old token it has stored.

The term "non-volatile storage" in this document refers to a data storage module that persists across restarts of the token maker. Examples of such a storage module include an internal disk, an internal flash memory module, an external disk, and an external database. A small non-volatile storage module is required for a token maker, but a larger one can be used to enhance performance, as described in Section 8.2.


Edition : 11
File Size : 1 file , 36 KB
Number of Pages : 22
Published : 06/01/2011

History


Related products

IETF RFC 3865
Published Date: 09/01/2004
A No Soliciting Simple Mail Transfer Protocol (SMTP) Service Extension
$10.8

Best-Selling Products

INCITS 100-1989(R1995) Add. 1:1991
Published Date: 01/01/1991
Addendum 1 to ANSI/NCITS X3.100-1989, Interface Between DTE & DCE for Packet Mode Operation with Packet Switch Data Communications Networks - NUI and NUI-Derived Facility Extensions (formerly ANSI X3.100-1989(R1995) Add.1:1991)
INCITS 100-1989(R1995)
Published Date: 01/01/1989
Interface Between DTE & DCE for Packet Mode Operation with Packet Switch Data Communications Networks (CCITT X.25) (formerly ANSI X3.100-1989(R1995)
INCITS 103-1983(R1996)
Published Date: 01/01/1983
Unrecorded Magnetic Tape Minicassette For Information Interchange, Coplanar 3.81 mm (0.150 Inch) (formerly ANSI X3.103-1983(R1996))
INCITS 11-1990(R2002)
Published Date: 01/01/1990
Specification for General Purpose Paper Cards for Information Interchange (formerly ANSI X3.11-1990(R2002))
$18
INCITS 111-1986(R1997)
Published Date: 01/01/1986
Matrix Character Sets for Optical Character Recognition (OCR-M) (formerly ANSI X3.111-1986(R1997))
INCITS 112-1984(R1996)
Published Date: 01/01/1984
14-Inch (356 mm) Diameter Low Surface Friction Magnetic Storage Disk (formerly ANSI X3.112-1984(R1996))