Re: SIMCO with IPSec

Stephen Lyda <[email protected]> Thu, 04 Aug 2005 10:23:05 -0500
Newsgroups gmane.ietf.midcom
Message-ID <[email protected]>
Martin,

It really was not clear to me reading the latest draft that IPSec was an
option.

Thank you for the clarification.

-Stephen

Martin Stiemerling wrote:
> Hi Stephen,
> 
> --On Dienstag, 2. August 2005 13:35 Uhr -0500 Stephen Lyda
> <[email protected]> wrote:
> 
> | Greetings,
> |
> | I was wondering if someone could elaborate on the need for the use of
> | IPSec with the SIMCO protocol.
> |
> | If this protocol is designed to be light-weight and usable with lower
> | end middleboxes, then I do not understand why IPSec encapsulation would
> | be a firm requirement for all messages.
> |
> | For the most part, it seems to me that SIMCO messages are going to be
> | traveling on a local, firewalled, network...and not vulerable to many
> | malicious attacks from the outside world.
> |
> | It seems SIMCOs session establishment messages would be adequate enough
> | to authenticate the SIMCO agent with the middlebox.  The middlebox would
> | also have the option to reject or select configurations set up by the
> | agent.
> 
> SIMCO works fine in all scenarios  and basically there two cases to
> distinguish:
> 
> 1) running SIMCO in an "unsafe" environment, e.g., over the
> Internet or in local Ethernet-based network with shared links
> 2) running SIMCO in a closed/controlled environment.
> 
> You are referring to case 2). In this case there is indeed no need
> to run SIMCO over IPsec. IPsec is recommended to be used in case 1.
> However, it is up to you to decided whether you run SIMCO over IPsec
> or not.
> 
>  Martin