> Thanks for the clarifications. > > Then the trial and switch by failure is really addressing a different > issue, which is providing redundant IKE connection. > > The original question is on how to set up policy for nested tunnels. I think this is what Eric is going to address in his update to the DMTF whitepaper (which will be rolled into the next I-D of the policy model). Jamie