[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Question about draft-ietf-ipsec-arch-sec-03.txt



Chirs,

You provide simple examples of how ordering can be inferred from IP address
ranges or widlcarded addresses.  However, the set of selector supported by
IPsec in an SPD is more than just addresses and we have previously
explained why explicit ordering is needed, i.e., we have a 5+ dimensional
space and no total ordering can be applied to entries in that space, in
general.

For inbound traffic, we have an SPI to guide us to an SAD entry and an
opportunity to have backpointers in the SAD to guide us to appropriate SPD
entries.  The NOTE refers to the possible complexity that arises from
sharing SA bundles resulting from application of of different policies.

Steve




References: