Re: KINK should referenece to IKEv2?
Shoichi Sakane <[email protected]> Wed, 02 Feb 2005 11:14:06 +0900
| Newsgroups | gmane.ietf.kink |
|---|---|
| Message-ID | <[email protected]> |
> Somebody will need to help me (us) here: can > IKEv1 successfully establish 2401bis SA's? Can > IKEv2 successfully establish 2401 SA's? I'm _guessing_ > that the answer to both is "yes", but the big question > is whether there's anything in IKEv2 what is exchanged > across the wire to inform the other side whether it's > 2401 or 2401bis. If so, we may need a similar mechanism. Stephan Kent who is 2401bis author answered to my question in the ipsec mailing list: 2401bis implicitly establishes requirements for certain features for a key/SA management protocol to enable systems to make full use of the IPsec features defined in 2401bis. IKEv2 satisfies these requirements; IKE v1 does not. It's way too late to suggest that we degrade requirements in 2401bis to be backwards compatible with IKE v1. it seems that IKEv1 does not work on 2401bis.