[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Move TS to optional (RE: Don't remove TS from IKEv2)



On Mon, 25 Mar 2002, Dan Harkins wrote:
> IKEv2 is not configured to express that, the SPD is. Can you configure the
> SPD to express "ESP for FTP" or "ESP null for H.323"? If you can then that
> representation in the SPD is passed to IKEv2 when a packet matches that rule
> and no SA exists...

Well, remember that the SPD machinery can have local extensions -- the
RFCs specify minimum functionality only.

                                                          Henry Spencer
                                                       henry@spsystems.net