[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Q on Traffic Selector Payload



The reason they're in IKE_AUTH is because creation of
the first child SA is piggybacked on the initial
creation of the IKE SA. (so really the IKE-AUTH
is doing a CREATE_CHILD_SA simultaneously).

Radia


"Ricky Charlet" <rcharlet@speakeasy.net> wrote:
>Howdy,
>
>	Why are there TS payloads in both IKE_AUTH  and CREATE_CHILD_SA? 
>Section 2.9 "Traffic Selector Negotiation" seems to discuss the TS 
>payloads only in the context of CREATE_CHILD_SA.
>
>
>---
>Ricky Charlet
>(formerly with Sonicwall and before that Redcreek)
>rcharlet@alumni.calpoly.edu
>510.324.3163
>