[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: comments on 2401bis-01 - Transport mode by SGs
On Tue, Mar 02, 2004 at 07:13:05PM -0500, Mark Duffy wrote:
>
> ... transport mode MAY be used between security
> gateways or between a security gateway and a host. In the latter
> case, transport mode may be used to support IP-in-IP [Per96] or GRE
> tunneling [FaLiHaMeTr00] over transport mode SAs.
>
> Even in the former case (SG to SG) shouldn't the use of transport mode be
> limited to cases where some in-IP tunnelling mechanism is used? But, it
> might not be IP-and-IP or GRE; it could be L2TP, MPLS-in-IP, etc. So I
> suggest rewording this passage as follows:
Why forbid two security gateways from using transport mode to protect
other SG-to-SG traffic?