[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Question on SA Bundle



Oh, I need to expand my example a bit. I said

  "protocol = tcp" -> "use different SA-pair for each connection"

and got from values extracted from the packet

  TS for SA: protocol=tcp, src_port=x, dst=port=y

Before someone says: "but IKEv2 has address and port ranges! Your
implementation does not support those, if it just extracts values from
packet!"

Answer: it's all in the local policy definition. It can use any
suitable method of mapping the packet into TS data. Even, actually
using the SPD selector ranges.

  "address-range" -> "use SA with matched address-range"

and TS would contain the address range (instead of single
address). But the key issue is: IKE does not need to know about
this. It would just see the TS.