[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Do we actually need dynamic ports?



Excerpt of message (sent 4 April 2002) by Paul Hoffman / VPNC:
> This is an interesting question for IKE implementers: which would 
> make more sense to you?
> - Keep a policy marker around and add or subtract relative to the marker
> - Delete the old SA and create a new one when you want to add or subtract

Rekeying is a fine solution if you don't mind the added overhead,
provided that the handling of SA changeover gets cleaned up.  In IKEv1
it's not well specified; even if you avoid the interop problems it's
easy to get packet loss.  Tim Jenkins tried to fix that.

     paul