[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: inbound policy verification



[Hmm, I received your message more than 24 hours after it was sent. I
observed similar delay with Lewis's recent message - the copy sent directly
to me arrived much sooner than the copy via the list.]

> I'm sorry for any confusion resulting from the note in 
> section 5.2.  The inbound SPD is ordered, just like the outbound SPD.

Steve, I apologize for being slow. In what sense is the inbound SPD ordered?
The note in section 5.2.1 says quite explicitly that my implementation
should not stop if the first policy in the inbound SPD with selectors that
match the incoming packet would result in rejection, but should keep
searching. So any ordering of the inbound SPD will result in the same
packets being accepted and rejected. So it is effectively not ordered. I've
read and reread this subsection and I keep coming back to this conclusion.

Thanks,
Rich


Follow-Ups: