RE: help

"Jiang, Donghua (Jane)" <[email protected]> Tue, 4 Mar 2003 10:26:34 -0500
Newsgroups gmane.ietf.mpls,gmane.ietf.rsvp
Message-ID <B99995113B318D44BBE87DC50092EDA943A7A8@nj7460exch006u.ho.lucent.com>
Harish,

I don't think it is an issue of whether IPSec can or cannot be used in RSVP.  It is an issue of what we want IPSec to do with RSVP.

The concept of IPSec is to encode IP packets so no one can intercept the IP packets while the IP packets are in transit between two end points.  If we encode RSVP packet with IPSec, do we expect RSVP nodes in between to understand the encoded RSVP packet?

We could implement IPSec between two RSVP nodes, if we fear the link between the two RSVP nodes is not safe at all.  Then, implementing IPSec hop by hop between RSVP nodes along the path might be too much.  IPSec is generally meant to be applied in "end-to-end" situation rather than "hop-by-hop" situation.

Regards,
Jane D. Jiang

 

-----Original Message-----
From: Harish Kumtakar [mailto:[email protected]]
Sent: Tuesday, March 04, 2003 12:34 AM
To: [email protected]; [email protected]
Subject: help


hi,

      Why IPSEC can not be used in RSVP to care of security. 
Please throw some light on this aspect.

Regards
-harish


Harish Kumtakar
Samsung India Software Operations
Samsung Digital House
No. 67, Infantry Road
Bangalore - 560 001

Ph: 5550555 extn:2260