[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Q: SPD & IKE phase2 IDs



I interpret RFC2401 to require support for both cases:

> [No.1] :
> Phase 2(Quick Mode) ID payload
>         IDci = 192.168.20.5
>         IDcr = 192.168.21.8
>         ID Type = ID_IPV4_ADDR
> 
> or
> 
> [No.2] :
> Phase 2(Quick Mode) ID payload
>         IDci = 192.168.20.0/24
>         IDcr = 192.168.21.0/24
>         ID Type = ID_IPV4_ADDR_SUBNET
> 

This is a policy decision made by the administrator that is stored
in the policy bound to the SPD rule. A rule can generate new SAD
entries that are initialized from the packet (i.e. your case 1)
or they can generate an SAD entry that duplicates the filter defined
in the SPD (i.e. your case 2).

-Ben McCann

-- 
Ben McCann                              Indus River Networks
                                        31 Nagog Park
                                        Acton, MA, 01720
email: bmccann@indusriver.com           web: www.indusriver.com 
phone: (978) 266-8140                   fax: (978) 266-8111


References: