[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: IBM VPN Bakeoff Issues
Stephen Kent wrote:
> > 2) The encapsulation mode of all services offered MUST match that
> >encapsulation mode of the bundle as a whole.
>
> Well, remember that a bundle can apply to traffic terminating at two
> different endpoints, specifically the required combination of a tunnel SA
> to an SG with a transport SA to a host behind the SG.
Precisely. And what about ESP in tunnel mode, wrapped with AH in
transport mode between 2 SGs?
I recognize all too well how these restrictions would simplify
processing, but don't think that makes for a good reason to modify the
spec.
Follow-Ups:
References: