some questions about draft-ietf-ipsp-ipsec-conf-mib-06.txt

"Reinartz, Norbert" <[email protected]>
Newsgroups gmane.ietf.ipsp
Message-ID <[email protected]>
There are a few questions about the 'IPsec Policy Configuration MIB':

How to configure preconfigured SAs?
The transformations of ipsec tunnels are described within 2 SAs, where each
SA describes the transformation of incoming or outgoing traffic.
Using the 'IPsec Policy Configuration MIB', we have to configure two
ipspSaPreconfiguredActionEntries.
In which way should these two entries be joined with the correspondent
filter(s)?

There are two ways, I think:
1. Separate configuration for each direction. Each direction is configured
with a separate ipspIpHeaderFilterEntry, ipspRuleDefinitionEntry and
ipspGroupContentsEntry. One ipHeaderFilter is configured for outgoing
traffic (filter describes unprotected data) and one filter for incoming
traffic (filter describes protected data, i.e. considering AH or ESP
protocol).
2. The tunnel is configured with one rule and one filter. The two
ipspSaPreconfiguredActionEntries are joined with the ipspRuleDefinitionEntry
using a ipspCompoundActionEntry and two ipspSubactionsEntries. The
ipspIpHeaderFilterEntry is used for matching outgoing traffic. The filter
for incoming traffic isn't configured. It is created implicit by the
application (using the information which protocol transformation is used for
incoming traffic, ..).

Can someone describe, how the configuration of preconfigured SAs should be
done.

One more question:
I'm missing something like a parameter for the direction of filters. There
is no way to configure filters for outgoing, incoming or both directions of
traffic. Is there a general meaning of the direction, e.g. both?

Whats the state of the 'IPsec Policy Configuration MIB', is work going on? I
couldn't read anything new about the draft for long time.

Thanks

Norbert Reinartz
DATUS AG
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.