[IPsec] P2P VPN draft

2012-03-07 Thread Yaron Sheffer
Hi Steve, a few initial comments. * The draft is short and clear. Thanks for that! * I have a problem with the title (and even more, with the file name of the draft). P2P is usually perceived as peer-to-peer, which skews the discussion towards one particular use case, that of

Re: [IPsec] P2P VPN Problem Statement - why is this hard?

2012-03-07 Thread Yaron Sheffer
Hi Yoav, Steve, I'm not sure that this star-vs-mesh discussion is so important, because even if you choose the simplest star topology, data propagation is still required. Configuration of the satellites is simple: *everything* goes to the hub. But the hub needs to know which satellite to

Re: [IPsec] P2P VPN draft UNCLASSIFIED

2012-03-07 Thread Ulliott, Chris
Classification:UNCLASSIFIED How about dynamic mesh VPNs as a title as I think the dynamic part is key here and probably an important aspect of the use cases. Chris [This message has been sent by a mobile device] - Original Message - From: Yaron Sheffer [mailto:yaronf.i...@gmail.com]

Re: [IPsec] P2P VPN draft UNCLASSIFIED

2012-03-07 Thread Yaron Sheffer
Fine with me. Yaron On 03/07/2012 11:52 PM, Ulliott, Chris wrote: Classification:UNCLASSIFIED How about dynamic mesh VPNs as a title as I think the dynamic part is key here and probably an important aspect of the use cases. Chris [This message has been sent by a mobile device]

Re: [IPsec] P2P VPN draft UNCLASSIFIED

2012-03-07 Thread Stephen Hanna
Upon reflection, I can see how Point to Point VPNs is problematic as a description of the problem. Really it's more about dynamically creating SAs so that any endpoint or gateway can communicate directly with any other, as permitted by policy. And how can we do this in a manageable manner in a