[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: comments on 2401bis-01 - Transport mode by SGs



On Tue, Mar 02, 2004 at 07:13:05PM -0500, Mark Duffy wrote:
> 
>                      ... transport mode MAY be used between security
>    gateways or between a security gateway and a host.  In the latter
>    case, transport mode may be used to support IP-in-IP [Per96] or GRE
>    tunneling [FaLiHaMeTr00] over transport mode SAs.
> 
> Even in the former case (SG to SG) shouldn't the use of transport mode be 
> limited to cases where some in-IP tunnelling mechanism is used?  But, it 
> might not be IP-and-IP or GRE; it could be L2TP, MPLS-in-IP, etc.  So I 
> suggest rewording this passage as follows:

Why forbid two security gateways from using transport mode to protect
other SG-to-SG traffic?