[Mip6-firewall] HA behind firewall - proposal
Suresh Krishnan
suresh.krishnan at ericsson.com
Thu Jun 28 09:50:56 EDT 2007
Hi Folks,
I feel that a BCP for firewall admins would be the best way to
address the HA being behind a firewall.
* This firewall MUST NOT drop IPSec traffic bound to the Home Agent. The
home agent address needs to be configured on the firewall to explicitly
allow all IPSec traffic. If this traffic is found to be not legitimate,
a host based firewall or the HA implementation can drop the packet
* If an MN is providing services (i.e. allows incoming connections), the
firewall needs to allow connection requests with the MN HoA as the
destination address. The address(es) of such MN(s) need to be configured
on the firewalls
* The firewall MUST permit all HoT messages with a destination address
of a known MN HoA, if there was a HoTI message sent out with the same
source address. The firewall might verify if the home test init cookie
matches the one sent
I believe that these rules are reasonable, but some of these might not
be acceptable to firewall admins. But, since the home network is
providing a service, there is not much room to maneuver without changing
the MIP6 protocol and end nodes (which might be another option).
Cheers
Suresh
More information about the Mip6-firewall
mailing list