[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: ISAKMP Delete Payload
On Wed, 20 Sep 2000, Awan Kumar Sharma wrote:
> I am having a doubt in ISAKMP delete payload. One of the field specifies
> the number of SPI's in the delete payload. According to my understanding
> there will be two SPIs in the Delete payload for IPSec SA. One for the
> Inbound SA and the other for the Outbound SA. Please correct me if I am
> wrong.
Although the wording in the RFCs is confusing, I believe you're wrong.
IPsec SAs in Delete payloads are inbound (toward the sender of the Delete)
only. Delete is an announcement ("I'm no longer accepting traffic on
these SAs"), not a request. Note that the destination address is not
specified in Delete, so it must be taken to be the sender.
Henry Spencer
henry@spsystems.net
References: