some questions about draft-ietf-ipsp-ipsec-conf-mib-06.txt
"Reinartz, Norbert" <[email protected]>
| Newsgroups | gmane.ietf.ipsp |
|---|---|
| Message-ID | <[email protected]> |
There are a few questions about the 'IPsec Policy Configuration MIB': How to configure preconfigured SAs? The transformations of ipsec tunnels are described within 2 SAs, where each SA describes the transformation of incoming or outgoing traffic. Using the 'IPsec Policy Configuration MIB', we have to configure two ipspSaPreconfiguredActionEntries. In which way should these two entries be joined with the correspondent filter(s)? There are two ways, I think: 1. Separate configuration for each direction. Each direction is configured with a separate ipspIpHeaderFilterEntry, ipspRuleDefinitionEntry and ipspGroupContentsEntry. One ipHeaderFilter is configured for outgoing traffic (filter describes unprotected data) and one filter for incoming traffic (filter describes protected data, i.e. considering AH or ESP protocol). 2. The tunnel is configured with one rule and one filter. The two ipspSaPreconfiguredActionEntries are joined with the ipspRuleDefinitionEntry using a ipspCompoundActionEntry and two ipspSubactionsEntries. The ipspIpHeaderFilterEntry is used for matching outgoing traffic. The filter for incoming traffic isn't configured. It is created implicit by the application (using the information which protocol transformation is used for incoming traffic, ..). Can someone describe, how the configuration of preconfigured SAs should be done. One more question: I'm missing something like a parameter for the direction of filters. There is no way to configure filters for outgoing, incoming or both directions of traffic. Is there a general meaning of the direction, e.g. both? Whats the state of the 'IPsec Policy Configuration MIB', is work going on? I couldn't read anything new about the draft for long time. Thanks Norbert Reinartz DATUS AG