RE: help
"Jiang, Donghua (Jane)" <[email protected]> Tue, 4 Mar 2003 10:26:34 -0500
| Newsgroups | gmane.ietf.mpls,gmane.ietf.rsvp |
|---|---|
| Message-ID | <B99995113B318D44BBE87DC50092EDA943A7A8@nj7460exch006u.ho.lucent.com> |
Harish, I don't think it is an issue of whether IPSec can or cannot be used in RSVP. It is an issue of what we want IPSec to do with RSVP. The concept of IPSec is to encode IP packets so no one can intercept the IP packets while the IP packets are in transit between two end points. If we encode RSVP packet with IPSec, do we expect RSVP nodes in between to understand the encoded RSVP packet? We could implement IPSec between two RSVP nodes, if we fear the link between the two RSVP nodes is not safe at all. Then, implementing IPSec hop by hop between RSVP nodes along the path might be too much. IPSec is generally meant to be applied in "end-to-end" situation rather than "hop-by-hop" situation. Regards, Jane D. Jiang -----Original Message----- From: Harish Kumtakar [mailto:[email protected]] Sent: Tuesday, March 04, 2003 12:34 AM To: [email protected]; [email protected] Subject: help hi, Why IPSEC can not be used in RSVP to care of security. Please throw some light on this aspect. Regards -harish Harish Kumtakar Samsung India Software Operations Samsung Digital House No. 67, Infantry Road Bangalore - 560 001 Ph: 5550555 extn:2260