[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IBM VPN Bakeoff Issues



Stephen Kent wrote:
> > 2) The encapsulation mode of all services offered MUST match that
> >encapsulation mode of the bundle as a whole.
> 
> Well, remember that a bundle can apply to traffic terminating at two
> different endpoints, specifically the required combination of a tunnel SA
> to an SG with a transport SA to a host behind the SG.

Precisely. And what about ESP in tunnel mode, wrapped with AH in
transport mode between 2 SGs?

I recognize all too well how these restrictions would simplify
processing, but don't think that makes for a good reason to modify the
spec.


Follow-Ups: References: