[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: typical IPsec-based VPNs incl. modecfg vs. DHCP
"Scott G. Kelly" <scott@airespace.com> writes:
> In such cases, no SPD entries are consulted following the routing
> lookup, and the routing table (effectively) becomes the SAD/SPD. I think
> this has obvious issues in terms of satisfying the selector criteria you
> outlined in RFC2401, for the reasons I enumerated above.
This works fine for output processing, but not necessarily for input
processing.
-derek
--
Derek Atkins
Computer and Internet Security Consultant
derek@ihtfp.com www.ihtfp.com