[IPsec] Large Scale VPN

2011-12-08 Thread Yoav Nir
Hi all. The discussion has died down a bit, so I thought I'd chime in with proposed charter text. What do people think of the following? The first paragraph is taken from Steve's email of 18-Nov. Yoav In an environment with many IPsec gateways and remote clients that share an established

Re: [IPsec] Large Scale VPN

2011-12-08 Thread Paul Hoffman
On Dec 8, 2011, at 1:55 AM, Yoav Nir wrote: In an environment with many IPsec gateways and remote clients that share an established trust infrastructure (in a single administrative domain or across multiple domains), customers want to get on-demand mesh IPsec capability for efficiency.

[IPsec] IPsec MIB confusion

2011-12-08 Thread Paul Clark
In section 5 of the IPsec Security Policy Database MIB (RFC 4807), it makes reference to the spdIpHeaderFilterTable object in the overview and the tutorial, but that table is not listed in the MIB definition in section 6.What am I missing? -Paul

Re: [IPsec] Large Scale VPN

2011-12-08 Thread Yaron Sheffer
We as a group can commit to deliverable #1 and #3 (problem statement and standardized solution). But deliverable #2 (vendor protocols) is mostly out of our hands. So before we approve this charter, I would like to hear from people that represent vendors that they can commit to publish such a

Re: [IPsec] Large Scale VPN

2011-12-08 Thread Paul Hoffman
On Dec 8, 2011, at 10:14 AM, Yaron Sheffer wrote: We as a group can commit to deliverable #1 and #3 (problem statement and standardized solution). But deliverable #2 (vendor protocols) is mostly out of our hands. So before we approve this charter, I would like to hear from people that

Re: [IPsec] Large Scale VPN

2011-12-08 Thread Yoav Nir
On Dec 8, 2011, at 6:04 PM, Paul Hoffman wrote: On Dec 8, 2011, at 1:55 AM, Yoav Nir wrote: In an environment with many IPsec gateways and remote clients that share an established trust infrastructure (in a single administrative domain or across multiple domains), customers want to get

Re: [IPsec] Large Scale VPN

2011-12-08 Thread Yoav Nir
On Dec 8, 2011, at 8:14 PM, Yaron Sheffer wrote: We as a group can commit to deliverable #1 and #3 (problem statement and standardized solution). But deliverable #2 (vendor protocols) is mostly out of our hands. That's why I used review and help rather than write or produce. So before we

Re: [IPsec] Large Scale VPN

2011-12-08 Thread Paul Hoffman
On Dec 8, 2011, at 12:00 PM, Yoav Nir wrote: On Dec 8, 2011, at 6:04 PM, Paul Hoffman wrote: On Dec 8, 2011, at 1:55 AM, Yoav Nir wrote: In an environment with many IPsec gateways and remote clients that share an established trust infrastructure (in a single administrative domain or

Re: [IPsec] Large Scale VPN

2011-12-08 Thread Michael Richardson
I find the goals and schedule acceptable. Yoav == Yoav Nir y...@checkpoint.com writes: Yoav In an environment with many IPsec gateways and remote clients Yoav that share an established trust infrastructure (in a single Yoav administrative domain or across multiple domains),