|
|||||||||||
|
Re: [Hipsec] comments on new HIP draft
From: Pekka Nikander <pekka.nikander(at)nomadiclab.com>
Date: Wed Mar 19 2003 - 12:39:01 EST >> Section 5.5 NES packets >> >> - Several people objected to the requirement to hold up all packets on >> an old SPI while you are doing the rekeying, due to the latency >> (e.g., VoIP will not stand it). Instead, it was felt that old and >> new SPIs could coexist and old SPIs would be garbage-collected when >> their replay protection ran out. > > I'd tend to agree. I'd like to be able to have the old SPI and new SPI >> Section 7.4 >> - it was felt that Protocol Unreachable would be more appropriate >> message than Host Unreachable (which is usually sent from routers >> and may be misinterpreted) > > Well then one wouldn't be able to tell the difference between a host I would consider that a feature. :-) --Pekka Hipsec mailing list Hipsec@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/hipsec Received on Wed Mar 19 13:25:06 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:58 EDT |
||||||||||
|
|||||||||||