Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Design] road warrior and id field.

From: Kaustubh Kumbhalkar <Kaustubh.Kumbhalkar(at)lntinfotech.com>
Date: Sat Mar 29 2003 - 01:28:37 EST

>Kaustubh Kumbhalkar writes:

>The value of IDii is used by the responder to determine whether it

by I3 i meant the message MI3 - third message from initiator. ( i should have been more clearer).

anyways , then the point is that the responder should respond to the initiators 'source address' and not the address as specified by IDii.

in freeswan when we initiate a connection from the road warrior , the responder updates its connection information with the 'source addresss' of the road warrior.
while the security association is required to be made w.r.t the address specified by IDii.
if this is possible then ,this wil allow a road warrior to negotiate SA's for its home address (using IDii) while having foreign address as the
source address for its IKE packets.
anything wrong in this?

>> this way it is not possible to negotiate for an SA having address other

>ISAKMP SAs are between an initiator and responder and only protect

Do you need help?X

>* a transport or tunnel mode IPsec SA between the initiator and

>* a tunnel mode IPsec SA between addresses that are protected by the



Design mailing list
Design@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/design Received on Sat Mar 29 01:58:29 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:58 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library