[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Initial Contact Message processing



 In your previous mail you wrote:

    Not sure this is the best answer, but on the implementation that I work
    on we would require multiple phase 1 SAs with that device.  One for every
    every NIC ( IP address) owned by the device from which a phase 2
   negotiation
    would be started on.  Based on this thread we might be better off allowing
    all NICs to utilize the same SA.
   
=> MOBIKE stuff should remove the limitation, i.e., one IKE SA should be
able to manage IPsec SAs using different IP addresses of the multi-NIC
devices, at the condition the IPsec SAs are in transport mode of course.
And without strange hacks with its phase one ID.

Regards

Francis.Dupont@enst-bretagne.fr