seeking info on security model

"Ricky Charlet" <[email protected]>
Newsgroups gmane.ietf.l2tpext
Message-ID <7E49849DDCBEAA489C65292E8B8AE7E80F6511F3@zrc2hxm2.corp.nortel.com>
Howdy,

  I am wondering about security in the l2tpext-l2vpn and/or pseudowires
world. I'm new here in l2tpext and have not really done my homework in
terms of searching the archives or documents. But perhaps some here
would be kind enough to get me pointed in the right directions...

  So my question is: which form of IPsec processing is anticipated to be
the fit with l2tpext-l2vpn... plain old IPsec or rfc3193 style dynamic
session establishment IPsec?

  In plain old IPsec, the administrators must know the IP addresses of
both peers to configure the policies. That seems likely to be true in
most l2vpn cases except perhaps for places where there is an intervening
NAT.

  In rfc3193 style IPsec, the administrator need not know the IP address
of the peer to configure policy. This was intended for use with remote
access clients (typically behind NATs) making connections to a remote
access gateway.

  Have these options for securing l2tpext-l2vpn / pseudowires been
discussed here before?


---
Ricky Charlet
W: 408.754.1733
[email protected]
--- _
   ( )  ASCII ribbon campaign 
    X    - against HTML email
   / \
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.