[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: typical IPsec-based VPNs incl. modecfg vs. DHCP



"Scott G. Kelly" <scott@airespace.com> writes:

> In such cases, no SPD entries are consulted following the routing
> lookup, and the routing table (effectively) becomes the SAD/SPD. I think
> this has obvious issues in terms of satisfying the selector criteria you
> outlined in RFC2401, for the reasons I enumerated above. 

This works fine for output processing, but not necessarily for input
processing.

-derek

-- 
       Derek Atkins
       Computer and Internet Security Consultant
       derek@ihtfp.com             www.ihtfp.com