Re: model, granularity and ranges

Eric Vyncke <[email protected]>
Newsgroups gmane.ietf.ipsp
Message-ID <[email protected]>
Wes

This is a good point and I would follow your recommendation but rephrased 
it like 'when the IPHeadersFilter specifies an IP address range then the 
Granularity property cannot be set to 1 (= subnet).

What do you think ?

I would amend the -06 with this

-eric


At 15:05 9/05/2002 -0700, Wes Hardaker wrote:


>Currently, the model has decided to use the IPHeadersFilter from PCIMe
>(which is a good thing I think), but the IPHeadersFilter object allows
>for filtering one:
>
>1) an adddress
>2) a subnet
>3) a range of address (eg: 10.0.0.5 - 11.1.2.3)
>
>#3 supports the ability to filter on a range of addresses that does
>not necessarily lie directly across a normal subnet definition.
>
>The question is what to do when the filter is a range of addresses but
>the Granularity property of the IPsecAction object is set to
>"subnet".  What is the selector supposed to look like for an SA in
>this case?  I'd suggest that it should be a singe address.  I think
>the full list of choices are:
>
>1) a single address (my recommendation).
>2) a subnet that most widely selects the matched address but still
>    falls entirely within the range (ick, but doable).
>3) multiple #2s such that multiple SAs are developed to completely
>    cover the range in question (even more ick, but still doable).
>
>Thoughts?
>
>--
>Wes Hardaker
>NAI Labs
>Network Associates
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.