1 Sep 2005 04:25
Re: comments/questions on draft-ieft-mip6-ikev2-ipsec-02.txt
Shinta Sugimoto <shinta <at> sfc.wide.ad.jp>
2005-09-01 02:25:31 GMT
2005-09-01 02:25:31 GMT
Hello Francis, On Wed, 31 Aug 2005 16:49:43 +0200 Francis Dupont <Francis.Dupont <at> enst-bretagne.fr> wrote: > In your previous mail you wrote: > > o The home agent and mobile node MUST have equivalent settings of > security policy in terms of granularity of upper layer protocol > specified in the traffic selector. > > => there was a long discussion about SPD mismatch between IKE peers > in the IPsec mailing list. It seems the TS exchange helps to detect > this kind of problems but IMHO even it should be common sense we can > repeat the policies at each side must match. > (PS: TSs are not enough, for instance they don't always show if a > SA pair can be shared... IMHO their indications are mainly negative, > and of course they never repair misconfigs). OK. TS negotiation seems to be (to some extent) helpful to detect the mismatch of security policy between the peers. > - Section 6.1.2, I found that some of the selector information does > not contain src addr, dst addr (or both). Is there any specific > reason for this ? In addition, I found description of inner src/dst > addr information as a part of SPD entry but is it needed ? > > => the inner addresses are part of the selectors (if the abstract > syntax for SPD entries was used, this kind of questions would be > avoided).(Continue reading)
RSS Feed