Re: SIMCO with IPSec
Stephen Lyda <[email protected]> Thu, 04 Aug 2005 10:23:05 -0500
| Newsgroups | gmane.ietf.midcom |
|---|---|
| Message-ID | <[email protected]> |
Martin, It really was not clear to me reading the latest draft that IPSec was an option. Thank you for the clarification. -Stephen Martin Stiemerling wrote: > Hi Stephen, > > --On Dienstag, 2. August 2005 13:35 Uhr -0500 Stephen Lyda > <[email protected]> wrote: > > | Greetings, > | > | I was wondering if someone could elaborate on the need for the use of > | IPSec with the SIMCO protocol. > | > | If this protocol is designed to be light-weight and usable with lower > | end middleboxes, then I do not understand why IPSec encapsulation would > | be a firm requirement for all messages. > | > | For the most part, it seems to me that SIMCO messages are going to be > | traveling on a local, firewalled, network...and not vulerable to many > | malicious attacks from the outside world. > | > | It seems SIMCOs session establishment messages would be adequate enough > | to authenticate the SIMCO agent with the middlebox. The middlebox would > | also have the option to reject or select configurations set up by the > | agent. > > SIMCO works fine in all scenarios and basically there two cases to > distinguish: > > 1) running SIMCO in an "unsafe" environment, e.g., over the > Internet or in local Ethernet-based network with shared links > 2) running SIMCO in a closed/controlled environment. > > You are referring to case 2). In this case there is indeed no need > to run SIMCO over IPsec. IPsec is recommended to be used in case 1. > However, it is up to you to decided whether you run SIMCO over IPsec > or not. > > Martin