[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Initial Contact Message processing
In your previous mail you wrote:
Not sure this is the best answer, but on the implementation that I work
on we would require multiple phase 1 SAs with that device. One for every
every NIC ( IP address) owned by the device from which a phase 2
negotiation
would be started on. Based on this thread we might be better off allowing
all NICs to utilize the same SA.
=> MOBIKE stuff should remove the limitation, i.e., one IKE SA should be
able to manage IPsec SAs using different IP addresses of the multi-NIC
devices, at the condition the IPsec SAs are in transport mode of course.
And without strange hacks with its phase one ID.
Regards
Francis.Dupont@enst-bretagne.fr