[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: issue with "per-interface SAD/SPD"

 In your previous mail you wrote:

   FYI, we addressed this sort of issue in draft-touch-ipsec-vpn-05.txt, 
   which was submitted independently as an Informational in April.
=> this is a very nice news!

   Introducing an interface selector is insufficient; the selector needs to 
   indicate the next-hop IP address and interface, as both are required for 
   IP forwarding. The details of this issue, and simpler alternatives are 
   discussed in the draft.
=> the problem I tried to address is a bit different: for instance in
Mobile IPv6 only the packets with a Mobility Header must be protected,
so a transport interface over the IP-in-IP tunnel is too much...
In fact, my message was mainly for the 2401bis authors, as the "per
interface" stuff is clearly inadapted.