[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: Don't remove TS from IKEv2




An id or name (I mean phase 2 sa id, not phase 1) can represent the "scope",
either it's a single address, or the combination of 10 adresses and 5
subnets and 6 ranges and 3 sevices.  

Besides, how do you decide if tunnel can be created if the "scopes" are a
little different, or must be exact matched?  How about it's dynamic scope?
It's better to take it out of IKE or put it as optional.

Michael Shieh

> -----Original Message-----
> From: Bill Sommerfeld [mailto:sommerfeld@east.sun.com]
> Sent: Wednesday, March 20, 2002 11:57 AM
> To: Michael Choung Shieh
> Cc: IP Security List
> Subject: Re: Don't remove TS from IKEv2 
> 
> 
> > I would say agree on a simple id or name is easier than on a complex
> > selector under heterogenous adminstration.
> 
> That doesn't solve the problem.
> 
> A name says *who* I'm talking to.
> 
> The TS selectors specify the *scope* of the SA's that are being
> negotiated (i.e., address only, or 5-tuple, or ..).
> 
> 						- Bill
>