SIMCO with IPSec

Stephen Lyda <[email protected]> Tue, 02 Aug 2005 13:35:14 -0500
Newsgroups gmane.ietf.midcom
Message-ID <[email protected]>
Greetings,

I was wondering if someone could elaborate on the need for the use of
IPSec with the SIMCO protocol.

If this protocol is designed to be light-weight and usable with lower
end middleboxes, then I do not understand why IPSec encapsulation would
be a firm requirement for all messages.

For the most part, it seems to me that SIMCO messages are going to be
traveling on a local, firewalled, network...and not vulerable to many
malicious attacks from the outside world.

It seems SIMCOs session establishment messages would be adequate enough
to authenticate the SIMCO agent with the middlebox.  The middlebox would
also have the option to reject or select configurations set up by the agent.

-Stephen