> You're right that it would be nice to have the capability to express
> a list of networks, and then manage a single SA pair instead
> of 2 pairs or
> 5 pairs or whatever. But I don't see this as one of the
> "needed it yesterday"
> problems (as was mentioned earlier in this thread). I think
> it fits more into
> the "if it ain't broke" catagory since there is a way to
> solve this problem.
> It's a tad annoying but it's not that bad. I think this can wait.
I agree with your above statement. It would be nice to have for IPSecond though and I think it is a small thing that makes this technology more usable to users.