Hi, After some thinking, I also feel that providing kind of flexibility is good. It is really going to solve the problem of creating security tunnel between two sites, having multiple subnets, when combined with services.
To support, this kind of flexibility, current TS is not good enough. Based on example given, 3000 Traffic Selectors need to be sent ( Did I get my math correct? ) which results to 40K of data in IKE message.
I could think of two approaches. - Provide flexibility in TS, where IP address ranges represented independently from Port ranges. - TS payload carrying symbolic name
I see that rfc2401bis talks about symbolic name and same can be sent in TS to facilitate this.
I hope, IKEv2 can accommodate this.
Thanks Ravi