Re: issue 19 -- same addresses for both directions?
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote: How do you folks feel about this? Please post your comments by Friday, June 3rd. => note I consider that I am not bound by your short delays... It seems we lost the basic idea: the only critical thing is the destination address the peer uses to send packets to us, and we really need to control it, this is why the option 3 for issue 20 is *not* the right one. About issue 19, I believe: - an SA pair MUST be created with the same address pair (just to avoid to provide a way to do something else) - an SA pair SHOULD use the same address pair (this doesn't close the door and avoid a spurious requirement). Regards [email protected] PS: to come back to issue 20, it doesn't exist in my address set management framework because it uses the option 2 (use primary address) initialized by the addresses IKE runs over (i.e., without crazy filtering on the path the address pair is proved to work by IKE itself :-). BTW I don't provide a way to use different address pair per way, only per SA pair (which IMHO is enough to support SCTP[-like] contexts).