Re: [IPsec] [TICTOC] Review request for IPsec security for packet based synchronization (Yang Cui)

2011-10-17 Thread Paul_Koning
>I cannot answer for the performance but if I was worried about making sure I >got the correct time I'd be more likely to be concerned about authenticating >the server than encrypting the contents. Encryption doesn't do a thing for >ensuring you got a valid packet. You don't need data confident

Re: [IPsec] New -00 draft: Creating Large Scale Mesh VPNs Problem Statement

2011-10-17 Thread Michael Richardson
> "Yoav" == Yoav Nir writes: Yoav> I definitely think that the authors of this draft (I'm mostly Yoav> just the editor) need a good answer about why RFC 4322 doesn't Yoav> cover the use cases. Mostly, the starting point is different. Yoav> RFC 4322 begins with nodes that hav

Re: [IPsec] New -00 draft: Creating Large Scale Mesh VPNs Problem Statement

2011-10-17 Thread Ulliott, Chris
The challenge for us is around discovery of the next cryptographic hop combined with the increase use of VoIP and other protocols that need peer to peer connectivity / low latency etc. If I'm sat behind a gateway and send a packet to a.b.c.d - my gateway needs to perform a lookup to find out wh