[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: IP comression - Can this be made optional?
>
> > When you have an SA bundle consisting of AH, ESP and
> > Compression protocols defined for a class of packets,
> > I understand, the entire SA bundle is required to be
> > applied on packets in either direction.
>
> No, an SA bundle is unidirectional, just like the SAs themselves. In
> principle, the set of SAs connecting two systems could be asymmetric.
> (And there are situations where this would be worthwhile, e.g. a highly
> asymmetric communications link might want compression on only the slow
> side.) The "Security Architecture" draft says quite explicitly that
> there are separate SPDs for inbound and outbound traffic.
>
Are you refering to setting up asymetric SAs without
the aid of IKE?
cheers,
suresh
Follow-Ups:
References: