[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Do we actually need dynamic ports?
Excerpt of message (sent 4 April 2002) by Paul Hoffman / VPNC:
> This is an interesting question for IKE implementers: which would
> make more sense to you?
> - Keep a policy marker around and add or subtract relative to the marker
> - Delete the old SA and create a new one when you want to add or subtract
Rekeying is a fine solution if you don't mind the added overhead,
provided that the handling of SA changeover gets cleaned up. In IKEv1
it's not well specified; even if you avoid the interop problems it's
easy to get packet loss. Tim Jenkins tried to fix that.
paul