Hi Steve,
I somehow feel that placing additional restrictions on selecting an IPsec SA is not very good just based on performance reasons. Why was a 32 bit sequence selected the first time, and how did we endup trying to extend it now.
If we look at how we ended up with only 4 bytes for the IP address instead of a variable length IP address: there too, it could be performance and other reasons that prompted people to go with a 4 byte IP address. I can see people arguing that 4 bytes of IP address, yes, we will never have enough nodes to use up all those addresses. We did endup using or scrambling all our IP addresses, and now moving to IPv6 just becuase we are running out out IPv4 addresses.
I think we should not place those restrictions just for performance reasons.
thanks, chinna