[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: more...changes to ISAMKP/Oakley
I think the change as proposed by Dan (i.e., allowing a DOI value of
zero for Phase 1 negotiations) is fine.
OTOH, I'm having a difficult time seeing the need for a separate
ISAKMP/Oakley DOI, or for eliminating/deprecating PROTO_ISAKMP.
Using a DOI of zero in Phase 1 should achieve whatever "logical
separation" between IPsec and ISAKMP might be desired. PROTO_ISAKMP
is defined as a reserved value across all DOIs (see the isakmp-08
draft, section A.2.2), and I see no reason why that should not
continue to be the case. Unless there's some additional justification
for these changes, I'd rather see things remain as they are.
-Shawn Mamros
E-mail to: smamros@newoak.com
Follow-Ups: