[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Q about SA bundles



Ricky,

That's a fair question.

Originally, one could have an SA that embraced both AH and ESP, but they
became separated some time ago, as part of the refinement of the IPsec
architecture, and the fleshing out of the ESP definition.  Also, the
definition of an SA changed to call for inclusion of the IPsec protocol as
part of the triple (dest addr, protocol, and SPI).

I think a (the?) major motivation for this separation is the desire to be
able to share SAs among multiple traffic flows, which argues for more the
discrete definition of SAs that we now have.

Steve


References: