[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

ipsec interoperability questions



Hi all,

A question on 'INITIAL-CONTACT' notification.

Is it okay to send 'INITIAL-CONTACT' as a payload in the Quick Mode
exchange.
(It seems to be so as per RFC 2407 section 4.6.3 - actually as per-the-rfc
it seems to be the preferred method given the potential active substitution
attack on notify messages with Main Mode).

Would there be any interoperability problems if 'INITIAL-CONTACT' is
implemented as a Quick-Mode payload?

Thanks for any input,

-- sankar ramamoorthi --