> Just a few notes re this discussion:
- the revised ESP/AH documents emphasize that an IPsec
implementation need not use the protocol type for SPI
differentiation. so, if one starts assuming this is true, it will be
yet another conflict with the IPsec specs
Curious what are the reasons for removing this restriction, and what are
the cons of still reqiring that this restriction apply.
- do I understand correctly that you are suggesting a change
to the specs to reduce the effective SPI space by a factor of 65K?
is everyone comfortable with this?
Steve
I am suggesting that the original concept of IPsec SA being identified by
a tuple: destination IP, protocol, SPI be required, and within the SPI add
new semantics for picking a SPI on the phase2 responder.