[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

IPsec DOI v7 - comment



Elfed T. Weaver writes:

> Protocol ID              Value
> RESERVED                0
> PROTO-ISAKMP        1
> PROTO-IPSEC-AH      2
> PROTO-IPSEC-ESP     3
> PROTO-IPCOMP         4
> 
> Q. When is it possible to negotiate a PROTO-ISAKMP SA AND 
> PROTO-IPSEC-* SA "at the same time" 
> 
> 
> Is it not the case that :
> PROTO-ISAKMP is negotiated in phase 1 ONLY and
> PROTO-IPSEC-*  negotiated in phase 2 ONLY

Or alternatively that the IKE draft provides (in addition to a generic
Key Exchange method) a phase 1 DOI?  It would be nice if we could
(perhaps for IPsecond) sit down and clean up these drafts, splitting the
IKE draft into logically unrelated IKE and Oakley-DOI documents.

ben



References: