>Kaustubh Kumbhalkar writes:
>The value of IDii is used by the responder to determine whether it
by I3 i meant the message MI3 - third message from initiator. ( i should have been more clearer).
anyways , then the point is that the responder should respond to the initiators 'source address' and not the address as specified by IDii.
in freeswan when we initiate a connection from the road warrior , the responder updates its connection information with the 'source addresss' of the road warrior. while the security association is required to be made w.r.t the address specified by IDii. if this is possible then ,this wil allow a road warrior to negotiate SA's for its home address (using IDii) while having foreign address as the source address for its IKE packets. anything wrong in this?
>> this way it is not possible to negotiate for an SA having address other
>ISAKMP SAs are between an initiator and responder and only protect
>* a transport or tunnel mode IPsec SA between the initiator and
>* a tunnel mode IPsec SA between addresses that are protected by the
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:58 EDT