State
Click on the red underlined text to get to the source
... When leveraging DHCPv4, configuration and addressing state is
kept on the DHCP server, not within the IKE implementation ...
... tunnel server does not result in the
loss of configuration and addressing state, thus making it
easier to support fail-over [12 ...
... IP address; only filled in if client is in
BOUND, RENEW or REBINDING state.
yiaddr 4 'your' (client) IP address ...
... correct IPsec tunnel, without having to keep state gleaned from the
DISCOVER, such as a table of the xid, chaddr and tunnel.
...
... tunnel endpoint. Note that this is particularly
undesirable in large VPN servers where the resulting state will be
substantial.
...
... Since IKECFG creates a separate pool of address state, it
complicates the provisioning of network utility-class ...
... 3] assumes that a DHCPREQUEST will not contain a
filled in giaddr field when generated during RENEWING state, the
DHCPACK will be sent directly to the client ...
... expecting it. As a result, it is either necessary for the security
gateway to add special code to avoid forwarding such packets, or to
wait until REBINDING state. Since [3] does not specify that the
giaddr field cannot be filled in when in the REBINDING state ...
... state. Since [3] does not specify that the
giaddr field cannot be filled in when in the REBINDING state, the
security gateway may put its own address ...
... security gateway may put its own address in the giaddr field when in
REBINDING state, thereby ensuring that it can receive the renewal
response without treating it as a special case.
...
