[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: same SPI/different exchange
Bill Sommerfeld writes:
> > What is the intended behavior of IKE if you
> > receive a proposal for a SPI which already exists?
>
> If this happens, the peer is probably buggy ..
Really? Doesn't this happen as a natural consequence of
retransmissions?
> > Should the old one be deinstalled and the new one installed?
>
> This sounds like the robust thing to do; I'd want to be careful to
> ensure that the old and new instances were treated as "different"
> (from the point of view any caching which might be going on..)
Right. They could change proposals, etc too.
Mike
Follow-Ups:
References: