[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IBM VPN Bakeoff Issues



  Not with IKE. What you're asking for is AH protecting ESP protecting
foo. To clarify the AH offer (that it's for ESP) you need client IDs
that say "This offer applies to protocol 50". To clarify the ESP offer
(that it's for foo) you also need client IDs that say "This offer applies
to foo". You can't express all that together in one offer. The same goes
for PFS. If you want group 5 for ESP and group 1 for AH you can't do it
all in one offer. It has to be separate.

  Dan.

On Fri, 06 Nov 1998 17:38:24 PST you wrote
> 
> Suppose someone in the future, for some reason we don't understand now,
> wants to use AH transport wrapped around ESP tunnel, directly between two
> hosts? Could this be negotiated with one proposal asking for AH-transport +
> ESP-tunnel?
> 
> Rich


References: