[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Fwd: Re: Son of IKE: A proposal for moving forward
On Thu, 13 Jun 2002, Stuart Jacobs wrote:
>...we need end-to-end SAs between our network
>elements with the SAs originating/terminating directly on the net
>interfaces within the elements. A VPN approach typically is deployed to
>interconnect two trusted networks over an untrusted third network...
There is no reason why the two trusted "networks" can't be single hosts --
that's just a degenerate case. It involves both minor complications and
minor simplifications, and is, as Paul said, a common VPN situation.
Henry Spencer
henry@spsystems.net