[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Do we actually need dynamic ports?



> Well the draft that Pyda wrote changes the payload so that it's NOT
> ambiguous (it tags each SA with a policy ID, so you always know
> exactly which traffic-policy you're talking about (even if your SPI's
> may change), and added an add/remove flag). 

I wasn't thinking of reordering within the KM protocol, but rather
reordering between the KM protocol and AH/ESP traffic, especially in 
the case of selector deletion.  

If the SPI changes, we reduce selector-set changes to the same
[un]solved problem as graceful rekeying ;-)

					- Bill