[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Addresses in traffic selectors in IKEv2



At 5:30 PM -0800 3/18/02, Mike Ditto wrote:
>  > >There is no advantage to having multiple types in this case, so we should
>>  >ditch the less generic ones.
>  >
>>  Paul makes a good point.
>>
>>  Ranges can be used to express what masks can express and so we should
>>  probably do away with masks. We should also prohibit trivial ranges
>>  that define a single address.
>
>I disagree; that seems to miss Paul's point.  Ranges are necessary and
>sufficient, and an address set should be composed of a list of ranges.

Mike is correct: what I propose is that we use ranges *only* so that 
there is not two ways to express the same thing. If there are two 
ways to express the same thing, we lose interoperability.

--Paul Hoffman, Director
--VPN Consortium