Media Description for IKE in SDP draft-saito-mmusic-sdp-ike-01 Makoto Saito Dan Wing
Purpose Setting up IPsec (IKE) Using SIP –VPN to a home router (or NAT device), etc. SIP Proxy Remote Client Home Router Home Network (1)INVITE Transaction (2) IKE (Media Session) (4) Tunnel Mode IPsec (3) Validate Fingerprint of Certificate Comedia-tls (RFC4572) for Self-Signed Certificate Auth ( a=fingerprint in SDP)
SIP or DNS? Static DNSDynamic DNSSIP Name Resolution to Floating IP Address -Support Authentication & Authorization -- Delegate to 3rd Party No Signed Cert No Whitelist UDP Hole Punching (ICE) for IKE & IPsec --Applicable Deployment-- Prompt Re-use of Provider’s Existing SIP Infrastructure
Functionally the same as Comedia-tls (RFC4572) –a=fingerprint which must match TLS/IKE certificate –Like IPsec, TLS can also create a tunnel (SSL VPN, WebVPN) SDP-IKE is...
Next Step Good idea to move forward in MMUSIC WG? (after the confirmation of Security ADs) Any Comments?