model, granularity and ranges

Wes Hardaker <[email protected]>
Newsgroups gmane.ietf.ipsp
Organization Network Associates - NAI Labs
Message-ID <[email protected]>

Currently, the model has decided to use the IPHeadersFilter from PCIMe
(which is a good thing I think), but the IPHeadersFilter object allows
for filtering one:

1) an adddress
2) a subnet
3) a range of address (eg: 10.0.0.5 - 11.1.2.3)

#3 supports the ability to filter on a range of addresses that does
not necessarily lie directly across a normal subnet definition.

The question is what to do when the filter is a range of addresses but
the Granularity property of the IPsecAction object is set to
"subnet".  What is the selector supposed to look like for an SA in
this case?  I'd suggest that it should be a singe address.  I think
the full list of choices are:

1) a single address (my recommendation).
2) a subnet that most widely selects the matched address but still
   falls entirely within the range (ick, but doable).
3) multiple #2s such that multiple SAs are developed to completely
   cover the range in question (even more ick, but still doable).

Thoughts?

-- 
Wes Hardaker
NAI Labs
Network Associates
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.