Re: model, granularity and ranges
Eric Vyncke <[email protected]>
| Newsgroups | gmane.ietf.ipsp |
|---|---|
| Message-ID | <[email protected]> |
Wes This is a good point and I would follow your recommendation but rephrased it like 'when the IPHeadersFilter specifies an IP address range then the Granularity property cannot be set to 1 (= subnet). What do you think ? I would amend the -06 with this -eric At 15:05 9/05/2002 -0700, Wes Hardaker wrote: >Currently, the model has decided to use the IPHeadersFilter from PCIMe >(which is a good thing I think), but the IPHeadersFilter object allows >for filtering one: > >1) an adddress >2) a subnet >3) a range of address (eg: 10.0.0.5 - 11.1.2.3) > >#3 supports the ability to filter on a range of addresses that does >not necessarily lie directly across a normal subnet definition. > >The question is what to do when the filter is a range of addresses but >the Granularity property of the IPsecAction object is set to >"subnet". What is the selector supposed to look like for an SA in >this case? I'd suggest that it should be a singe address. I think >the full list of choices are: > >1) a single address (my recommendation). >2) a subnet that most widely selects the matched address but still > falls entirely within the range (ick, but doable). >3) multiple #2s such that multiple SAs are developed to completely > cover the range in question (even more ick, but still doable). > >Thoughts? > >-- >Wes Hardaker >NAI Labs >Network Associates