[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Question on SA Bundle
Oh, I need to expand my example a bit. I said
"protocol = tcp" -> "use different SA-pair for each connection"
and got from values extracted from the packet
TS for SA: protocol=tcp, src_port=x, dst=port=y
Before someone says: "but IKEv2 has address and port ranges! Your
implementation does not support those, if it just extracts values from
packet!"
Answer: it's all in the local policy definition. It can use any
suitable method of mapping the packet into TS data. Even, actually
using the SPD selector ranges.
"address-range" -> "use SA with matched address-range"
and TS would contain the address range (instead of single
address). But the key issue is: IKE does not need to know about
this. It would just see the TS.