[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SPD Syntax Example



Andrew,

We've had this discussion before, and I'd rather not revisit it. If peers do not negotiate the selectors for an SA, interoperability problems arise. We have experience with this happening today, because IKE v1 did not do as well as IKE v2 in this regard. For example, in IKE v2 the initiator sends the packet header info for the packet that triggers SA creation, to allow the responder more flexibility in finding a suitable SPD entry when peers have overlapping but not identical SPD entries.

Steve