[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Question



Rohit,

	I saw Dan's Response to you message and just wanted to add to his
comment.  Specifically, on receipt, the lookup is performed based on dest
IP addr, security protocol, and SPI.  Thus lack of access to the port
fields is not an issue for SA lookup. Consistent with what Dan noted, the
arch doc calls for complete processing of all security protocols prior to
checking against the SA parameters, so the port fields are available at
that time.

Steve




References: