[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Fwd: Re: Son of IKE: A proposal for moving forward



On Thu, 13 Jun 2002, Stuart Jacobs wrote:
>...we need end-to-end SAs between our network 
>elements with the SAs originating/terminating directly on the net 
>interfaces within the elements.  A VPN approach typically is deployed to 
>interconnect two trusted networks over an untrusted third network...

There is no reason why the two trusted "networks" can't be single hosts --
that's just a degenerate case.  It involves both minor complications and
minor simplifications, and is, as Paul said, a common VPN situation. 

                                                          Henry Spencer
                                                       henry@spsystems.net