[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: quick mode "proxy" case



 In your previous mail you wrote:

       To add to ur question can anybody tell me how do we specify
   address range, say IPV4addressrange in proxy mode using identity payloads.
   
=> in the case I am interested to the only possible identity types
are ID_IPV4_ADDR and ID_IPV6_ADDR (names are at least complex/ambiguous
and subnets/ranges don't fit with transport mode).

   Also what i couldnt understand was, are u interested in IKE or IPsec role.
   Since IKE doesnt care whether its Tunnel or transport. It just exchanges the
   attributes and IDi,IDr. Local policies in IPsec does the rest
   
=> local policies are not a second order detail in the "proxy" case.
But we can look at the case where more than one SA is negociated
in a quick/phase 2 exchange...

Regards

Francis.Dupont@enst-bretagne.fr