Issue 171: IKEv2 over TCP
From: Bernard Aboba (abobainternaut.com)
Date: Thu, 11 Sep 2003 19:06:15 -0500 (CDT)
Issue 171: IKEv2 over TCP
Submitter name: Bernard Aboba
Submitter email address: aboba [at] internaut.com
Date first submitted: 9/11/2003
Reference:
Document: EAP-05
Comment type: T
Priority: S
Section: 2.2, 4.3
Rationale/Explanation of issue:

IKEv2 runs over UDP, not TCP as implied in Section 2.2 and 4.3.

In Section 2.2, change:

"TCP [IKEv2]" to "TCP [PIC]".

In Section 4.3, change:

" When run over a reliable lower layer (e.g., EAP over ISAKMP/TCP, as
within [IKEv2]), the authenticator retransmission timer SHOULD be set
to an infinite value, so that retransmissions do not occur at the EAP
layer. The peer may still maintain a timeout value so as to avoid
waiting indefinitely for a Request."

To:

" When run over a reliable lower layer (e.g., EAP over ISAKMP/TCP, as
within [PIC]), the authenticator retransmission timer MAY be set
to an artificially high value, so that retransmissions do not occur
at the EAP layer. The peer may still maintain a timeout value so
as to avoid waiting indefinitely for a Request."


Results generated by Tiger Technologies using MHonArc.