[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Deleting IPsec SA's




How do we do this?

When sending a Delete message, I only get to include one SPI, which I
would assume is the SPI of the SA terminating at my end.  But, I'm going
on assumption because I can't find anything in the documents which will
clarify.  Is there no way to tell the remote end that I'm no longer
going to be sending him packets under one of his SA's?  Do I have to
assume that the remote end is smart enough to kill his own SA's when I
delete the corresponding ones on my end?

This needs to be added to the DOI document.


ben