[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Addresses in traffic selectors in IKEv2



One of the most common configuration errors found in VPNC conformance 
testing is that people use the wrong address type in their traffic 
selectors. There are two ways to specify multiple addresses (ranges 
and subnets) and three ways to specify a single address (ranges, 
subnets, and address). This is silly.

IKEv2 should have exactly one way to specify either a single or 
multiple addresses: a range. IKE implementations *could* match the 
different types to each other (some implementations do that), but 
there is no reason to force them to.

--Paul Hoffman, Director
--VPN Consortium