model, granularity and ranges
Wes Hardaker <[email protected]>
| Newsgroups | gmane.ietf.ipsp |
|---|---|
| Organization | Network Associates - NAI Labs |
| Message-ID | <[email protected]> |
Currently, the model has decided to use the IPHeadersFilter from PCIMe (which is a good thing I think), but the IPHeadersFilter object allows for filtering one: 1) an adddress 2) a subnet 3) a range of address (eg: 10.0.0.5 - 11.1.2.3) #3 supports the ability to filter on a range of addresses that does not necessarily lie directly across a normal subnet definition. The question is what to do when the filter is a range of addresses but the Granularity property of the IPsecAction object is set to "subnet". What is the selector supposed to look like for an SA in this case? I'd suggest that it should be a singe address. I think the full list of choices are: 1) a single address (my recommendation). 2) a subnet that most widely selects the matched address but still falls entirely within the range (ick, but doable). 3) multiple #2s such that multiple SAs are developed to completely cover the range in question (even more ick, but still doable). Thoughts? -- Wes Hardaker NAI Labs Network Associates