seeking info on security model
"Ricky Charlet" <[email protected]>
| Newsgroups | gmane.ietf.l2tpext |
|---|---|
| Message-ID | <7E49849DDCBEAA489C65292E8B8AE7E80F6511F3@zrc2hxm2.corp.nortel.com> |
Howdy, I am wondering about security in the l2tpext-l2vpn and/or pseudowires world. I'm new here in l2tpext and have not really done my homework in terms of searching the archives or documents. But perhaps some here would be kind enough to get me pointed in the right directions... So my question is: which form of IPsec processing is anticipated to be the fit with l2tpext-l2vpn... plain old IPsec or rfc3193 style dynamic session establishment IPsec? In plain old IPsec, the administrators must know the IP addresses of both peers to configure the policies. That seems likely to be true in most l2vpn cases except perhaps for places where there is an intervening NAT. In rfc3193 style IPsec, the administrator need not know the IP address of the peer to configure policy. This was intended for use with remote access clients (typically behind NATs) making connections to a remote access gateway. Have these options for securing l2tpext-l2vpn / pseudowires been discussed here before? --- Ricky Charlet W: 408.754.1733 [email protected] --- _ ( ) ASCII ribbon campaign X - against HTML email / \