[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Simplifying IKE



Francis Dupont writes:
 > PS: I am not in favor to reduce IPsec to VPNs, the thing which will happen
 > if we remove AH then transport mode...

Francis,

I'm not in favor of VPN only IPsec either, but I don't
understand removal of AH would be a step in that direction.
The very existence of AH, I think, is at the root of 
a lot of the misunderstanding that happened with MIPv6.
It may not have eliminated all of the misuses of IPsec,
but it seems like a pretty vivid example of how more
options == more confusion of how they all work (or
don't work as the case were).

	      Mike


Follow-Ups: References: