[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: quick mode "proxy" case
In your previous mail you wrote:
To add to ur question can anybody tell me how do we specify
address range, say IPV4addressrange in proxy mode using identity payloads.
=> in the case I am interested to the only possible identity types
are ID_IPV4_ADDR and ID_IPV6_ADDR (names are at least complex/ambiguous
and subnets/ranges don't fit with transport mode).
Also what i couldnt understand was, are u interested in IKE or IPsec role.
Since IKE doesnt care whether its Tunnel or transport. It just exchanges the
attributes and IDi,IDr. Local policies in IPsec does the rest
=> local policies are not a second order detail in the "proxy" case.
But we can look at the case where more than one SA is negociated
in a quick/phase 2 exchange...
Regards
Francis.Dupont@enst-bretagne.fr