[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IPSEC SA bundle in SAD /RFC2401




> Dear Everyone,
>
>
> Can anyone of you tell me that, by standard  for an adjacent SA bundle
like
>
>            [IP] [AH] [ESP] [Upper]
>
> I should use two separated SA or use one SA but specify the two ALGs
> (and two keys)in one SA?

I think you should use two separated SA, one for AH and another for ESP. For
example, if your SA bundle like
        [IP] [AH] [ESP] [ESP] [Upper]
you should use three SAs.


Regards,

Li


>
> If I have to use one SA for AH, one SA for ESP, do AH later, do I have
> to tell SPD that now the outbound packet's selector value in transport
> is ESP?


> Thanks.
>
> Qu
>



References: