[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Protocol specific and port specific SAs



At 16:23 4.9.2000 +0300, Antonia wrote:

 >	So the thing here is: Should IKE send the protocol number specified
 >in the selector when the SA is shared? 

No. If you set it to tcp, you can only transmit tcp data through it.

Lots of us will filter on protocols, lists of port ranges, tcp directions
and whatever.
But you can't negotiate or announce that kind of filtering in IKE. Use
zeros in this case.

Jörn






References: