[IPsec] Issue 202 [was Issue #194] - Security Considerations should discuss the threat

2010-10-28 Thread Tero Kivinen
Frederic Detienne writes: > Like I explained earlier, sharing the address-less QCD token is > problematic in multiple practical network designs: > - Stateless failover pairs (e.g. VRRP, HSRP, ..) > - Load Balanced clusters > - Anycast server clusters I do not think having address inside the QCD

Re: [IPsec] Issue #194 - Security Considerations should discuss the threat

2010-10-28 Thread Tero Kivinen
Frederic Detienne writes: > In order to secure QCD, the token has to include all the fields that > can be used for routing a packet to any given server: > > - source/destinatition IP > - protocol (UDP / ESP) > - source/destination ports if applicable But the problem is that the IPsec implemen