[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: IKE negotiation for ICMP message type selectors
>> For example, we've had discussion on the list about using ICMP
>> message type fields in lieu of port fields, when ICMP was the
>> What do people think, and why?
>Particularly important for IKE and IPv6 (as, pending introduction of
>some facility to secure Neighbor Discovery) you likely want ND traffic
>in clear while other ICMPv6 traffic is protected.
we will need to do this every time new protocol becomes available.
i guess we should make the concept of "selector" more generic.
(for KAME implementation i'm thinking of switching to BPF-based policy)