[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Fwd: Re: Son of IKE: A proposal for moving forward



Excerpt of message (sent 13 June 2002) by Bill Sommerfeld:
> > There is no reason why the two trusted "networks" can't be single hosts --
> > that's just a degenerate case.  It involves both minor complications and
> > minor simplifications, and is, as Paul said, a common VPN situation. 
> 
> there are certain obvious scaling problems with this approach.
> 
> direct use of transport mode is likely to be easier to manage, require
> fewer addresses, and be simpler with large numbers of hosts.

Tunnel mode does not *require* more addresses than transport mode --
though it allows them.

       paul