[IPsec] Issue #219 - Star topology as an admin choice

2012-05-11 Thread Vishwas Manral
Hi, I would like to start off by trying to resolve the issue. The notes from the IETF are attached below. Description:Some admins prefer a star topology so they can inspect traffic. They may not want to use this technology. Detail arguments: My take is similar to what Yaron and Yaov seem to

[IPsec] Issue #213/ #214 - Allow for non-direct end point connectivity

2012-05-11 Thread Vishwas Manral
Hi, Description: Direct endpoint-to-endpoint connectivity may not be possible. Should gateways figure things out completely or just punt endpoints to a closer gateway? Detail Arguments: As Izaac and John Lesser pointed out this is more of a routing issue. Though current solutions do not allow

[IPsec] Issue #218 - Exhaustive configuration

2012-05-11 Thread Vishwas Manral
Hi, Description: Exhaustive configuration Detail Arguments:Tero rightly mentioned that the configuration is a proprietary issue. However there are a few things, that make the configuration hard. Change of IP address of a spoke, NAT, configuration limited by weakest link(device) in the chain.