[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Ipsec] Is AH + ESP required or needed in IKEv2



Title: RE: [Ipsec] Is AH + ESP required or needed in IKEv2
Tero,

Sorry for the confusion. The intent in 2401bis was to simplify, and thus to remove the special case of creating two SAs based on one SPD entry.  We missed the text in 4.4.1 that still accommodated the AH+ESP case.  We will remove it. This also avoids the confusion of whether both SAs are tunnel or transport mode when we had one SPD entry that called for negotiating a pair of SAs, but only one indication of modality, as you noted.

Steve

_______________________________________________
Ipsec mailing list
Ipsec@ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec