[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [saag] Re:



hi

>
> On Friday, May 24, 2002, at 11:00 , Derek Atkins wrote:
> > Because IPsec is hop-by-hop but you want RSVP end-to-end.
> >
> > -derek
>
> Hmm.  I would rather say that RSVP is hop-by-hop and
> that (normally) AH/ESP are end-to-end.

but no one prevents you from using ipsec ah/esp in a hop-by-hop mode for
protecting rsvp.
>
> However, if one used (for example) AH with an asymmetric algorithm,
> one could perform hop-by-hop authentication of the
> packet with AH.


what do you mean by "AH with an asymmetric algorithm" ? IKE with an
asymmetric authentiction mode?

> This has obvious computational cost
> issues so might not be the best choice.



ciao
hannes

>
> > SatishK Amara <kumar_amara@yahoo.com> writes:
> >
> >> Why don't you use IPSEC to secure RSVP.
> >>
> >> Satish Amara