[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: ISAKMP DOI Question (General, Not IP Specific)
> > - There can only be one SA between two machines at a given time.
> I suppose this depends on who owns the SA i.e. if the owner of an SA
> is identified by the IP addr only (and a host only has one IP addr)
> then IMHO there can be only one pair of unidirectional SAs between any pair of
> machines.
Why? The SA has an identifier; you can several SA's for the same identities
without fear of confusion.