1 Oct 2004 01:31
Re: revised IPsec Architecture draft (2401bis)
Francis Dupont <Francis.Dupont <at> enst-bretagne.fr>
2004-09-30 23:31:05 GMT
2004-09-30 23:31:05 GMT
In your previous mail you wrote: the source address, for the sender, is trivial if you have just one interface, and if you are not mobile. if you have multiple interfaces, you do need to specify the right one to use as the source address, statically. if you are mobile, you need to have something outside of IPsec updating the value, => an IPsec/mobile integrate code needs to know the place of the value to be enabled to update it: I raised the issue exactly for this reason... which says that there would not be any useful SPD entry to specify in advance. so, yes, we will add text to accommodate both source and destination addresses for tunnel headers. => so this issue is closed. >=> when? This is not clear that the SPD is decorrelated... I am afraid >the decorrelation goal is to focused on caching so I missed in 5: we do not explain how to perform decorrelation in detail the text, but rather refer to Appendix B. A fundamental requirement for any algorithm of this sort is that it breaks overlapping entries into non-overlapping entries. I think the text inn 4.4.1 says that reasonably well. => I have no problem with the decorrelation idea (I began with pattern matching and term rewriting systems where the problem is hard, BTW(Continue reading)
RSS Feed