[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SPI orthogonality



> > are the SAs
> > identified by tuples (SPI/Remote Address) or by (SPI/Remote
> > Address/Protocol), where Protocol = {AH, ESP} ?
> > - -Angelos
>
> The response was that the IPsec draft was in error (and would be modified).
> SA's are indexed by SPI/Remote Address/Protocol triplets.
> 
> ben

Yes, Ben is right.  You can have an ESP SA <SPI=0x2112, DST=224.0.0.1> while
having an AH SA also with <SPI=0x2112, DST=224.0.0.1>.

Dan


References: