[IPsec] draft-bhatia-moving-ah-to-historic

2012-04-16 Thread Nick Hilliard
I'd like to add a voice of support to this draft. AH adds little except complication to ipsec implementations and confusion to end users. Regarding ipv4 NATs, they are ubiquitous and will become more so once ipv4 scarcity is realised worldwide (particularly in asia, which is currently the

Re: [IPsec] draft-bhatia-moving-ah-to-historic

2012-04-16 Thread Yoav Nir
On Apr 16, 2012, at 1:53 PM, Nick Hilliard wrote: I'd like to add a voice of support to this draft. AH adds little except complication to ipsec implementations and confusion to end users. It only adds confusion and complication in the sense that telnet adds them (ESP is SSH in this

Re: [IPsec] draft-bhatia-moving-ah-to-historic

2012-04-16 Thread Nick Hilliard
On 16/04/2012 12:25, Yoav Nir wrote: It only adds confusion and complication in the sense that telnet adds them (ESP is SSH in this analogy). To be fair, it adds a lot more confusion than telnet vs ssh. With my !inex.ie hats on, I see smart but untrained ops people attempting to configure up