[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Ipsec] Number of Proposals in IKE_SA_INIT exchange for IKE_SA andfirst CHILD_SA ??
Yoav Nir writes:
> You need at least one proposal in an SA payload in message #1, and at
> least one proposal in an SA payload in message #3.
>
> If you do not include an SA payload in message #3, that says that you
> don't want to create a child-SA.
SAi2, and SAr2 are not optional in the current draft, thus there is
no way not to create the child-SA during the initial IKE exchange.
--
kivinen@safenet-inc.com
_______________________________________________
Ipsec mailing list
Ipsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec