[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: IPSEC SA bundle in SAD /RFC2401
> Dear Everyone,
>
>
> Can anyone of you tell me that, by standard for an adjacent SA bundle
like
>
> [IP] [AH] [ESP] [Upper]
>
> I should use two separated SA or use one SA but specify the two ALGs
> (and two keys)in one SA?
I think you should use two separated SA, one for AH and another for ESP. For
example, if your SA bundle like
[IP] [AH] [ESP] [ESP] [Upper]
you should use three SAs.
Regards,
Li
>
> If I have to use one SA for AH, one SA for ESP, do AH later, do I have
> to tell SPD that now the outbound packet's selector value in transport
> is ESP?
> Thanks.
>
> Qu
>
References: