[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Ipsec] Negotiating IKE_SAs



At 7:57 PM -0500 11/6/06, David Wierbowski wrote:
...

RFC 4301 discusses the use of the SPD to find acceptable policy for the creation of CHILD_SAs and it discusses the use of the PAD to authenticate IKE endpoints. It does not appear to define a construct to identify what policy is acceptable for the creation of a of an IKE_SA with a specific IKE peer. Does this mean that RFCs 4301 and 4306 do support the definition of peer specific policy for IKE_SAs?

The PAD not only says how to authenticate an IKE peer, it also provides a way to restrict the range of IDs or addresses asserted by the peer when the SPD is searched for a matching policy. In that sense there is a notion of peer-specific policies, but for child SAs, not for IKE SAs.

Steve

_______________________________________________
Ipsec mailing list
Ipsec@xxxxxxxx
https://www1.ietf.org/mailman/listinfo/ipsec