[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IP comression - Can this be made optional?



> 
> > When you have an SA bundle consisting of AH, ESP and 
> > Compression protocols defined for a class of packets,
> > I understand, the entire SA bundle is required to be 
> > applied on packets in either direction.
> 
> No, an SA bundle is unidirectional, just like the SAs themselves.  In
> principle, the set of SAs connecting two systems could be asymmetric. 
> (And there are situations where this would be worthwhile, e.g. a highly
> asymmetric communications link might want compression on only the slow
> side.)  The "Security Architecture" draft says quite explicitly that
> there are separate SPDs for inbound and outbound traffic.
> 

Are you refering to setting up asymetric SAs without 
the aid of IKE?

cheers,
suresh


Follow-Ups: References: