[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Don't remove TS from IKEv2



> > Besides, how do you decide if tunnel can be created 
> 
> two words:
> 
> "transport mode"

I'm sure Michael meant tunnel in the generic sense, not in the
encapsulation sense.  The point is that SOI should negotiate keys and
SAs, but since each endpoint already has a policy that it must apply
on every packet anyway, we don't need key management also to give
policy refinements.  Additionally, no existing or proposed traffic
selector notation can describe all commonly used services.

					-=] Mike [=-