[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Ipsec] Number of Proposals in IKE_SA_INIT exchange for IKE_SA andfirst CHILD_SA ??



Yoav Nir writes:
> You need at least one proposal in an SA payload in message #1, and at 
> least one proposal in an SA payload in message #3.
> 
> If you do not include an SA payload in message #3, that says that you 
> don't want to create a child-SA.

SAi2, and SAr2 are not optional in the current draft, thus there is
no way not to create the child-SA during the initial IKE exchange. 
-- 
kivinen@safenet-inc.com

_______________________________________________
Ipsec mailing list
Ipsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec