[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IKE negotiation for ICMP message type selectors

>> For example, we've had discussion on the list about using ICMP 
>> message type fields in lieu of port fields, when ICMP was the
>> payload.
>> What do people think, and why?
>Long overdue.  
>Particularly important for IKE and IPv6 (as, pending introduction of
>some facility to secure Neighbor Discovery) you likely want ND traffic
>in clear while other ICMPv6 traffic is protected.

	we will need to do this every time new protocol becomes available.
	i guess we should make the concept of "selector" more generic.
	(for KAME implementation i'm thinking of switching to BPF-based policy)