[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ISAKMP Delete Payload



On Wed, 20 Sep 2000, Awan Kumar Sharma wrote:
>   I am having a doubt in ISAKMP delete payload. One of the field specifies 
> the number of SPI's in the delete payload. According to my understanding 
> there will be two SPIs in the Delete payload for IPSec SA. One for the 
> Inbound SA and the other for the Outbound SA. Please correct me if I am 
> wrong.

Although the wording in the RFCs is confusing, I believe you're wrong.
IPsec SAs in Delete payloads are inbound (toward the sender of the Delete)
only.  Delete is an announcement ("I'm no longer accepting traffic on
these SAs"), not a request.  Note that the destination address is not
specified in Delete, so it must be taken to be the sender.

                                                          Henry Spencer
                                                       henry@spsystems.net



References: