[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ISAKMP DOI Question (General, Not IP Specific)



>   > - There can only be one SA between two machines at a given time.

>   I suppose this depends on who owns the SA i.e. if the owner of an SA 
>   is identified by the IP addr only (and a host only has one IP addr) 
>   then IMHO there can be only one pair of unidirectional SAs between any pair of 
>   machines.

Why?  The SA has an identifier; you can several SA's for the same identities
without fear of confusion.