[IPsec] documentation of pf_key extensions (not in rfc 2367)

2012-06-14 Thread Sec Pro
Hi, I do not know if this is the right place for posting my question, but I hope so. If not, I am very sorry for the inconvenience. I just started digging me into the topic of PF_KEY and the manually manipulation of the SAD and SPD from the user land of Linux. My problem is finding

Re: [IPsec] Updates to the IKEv2 Extension for IKEv2/IPsec High Availablity

2012-06-14 Thread Kalyani Garigipati (kagarigi)
Hi Zhang, Thanks for going through the RFC 6311 . I have gone through your proposed draft and felt that there is some confusion regarding the message id concept of ikev2. I have seen that in section 2.3 you were comparing the higer sender value of x2 with y2. That is wrong. when x2 proposes

Re: [IPsec] New Version Notification for draft-nir-ipsecme-ike-tcp-00.txt

2012-06-14 Thread Yoav Nir
Hi Yaron Responses are inline. Yoav On Jun 14, 2012, at 1:40 AM, Yaron Sheffer wrote: Hi Yoav, thank you for the new draft. A few comments: - Please mention the question of IKE keepalive messages (liveness check). Do you expect these messages to each be on a new connection? Or to

Re: [IPsec] New Version Notification for draft-nir-ipsecme-ike-tcp-00.txt

2012-06-14 Thread Yaron Sheffer
Hi Yoav, please see below. Thanks, Yaron On 06/14/2012 08:39 PM, Yoav Nir wrote: Hi Yaron Responses are inline. Yoav On Jun 14, 2012, at 1:40 AM, Yaron Sheffer wrote: Hi Yoav, thank you for the new draft. A few comments: - Please mention the question of IKE keepalive messages

Re: [IPsec] New Version Notification for draft-nir-ipsecme-ike-tcp-00.txt

2012-06-14 Thread John Leser
On 06/14/12 13:39, Yoav Nir wrote: Hi Yaron Responses are inline. Yoav On Jun 14, 2012, at 1:40 AM, Yaron Sheffer wrote: Hi Yoav, thank you for the new draft. A few comments: - Please mention the question of IKE keepalive messages (liveness check). Do you expect these messages to each be

Re: [IPsec] New Version Notification for draft-nir-ipsecme-ike-tcp-00.txt

2012-06-14 Thread Yoav Nir
On Jun 14, 2012, at 10:34 PM, John Leser wrote: On 06/14/12 13:39, Yoav Nir wrote: Hi Yaron Responses are inline. Yoav On Jun 14, 2012, at 1:40 AM, Yaron Sheffer wrote: Hi Yoav, thank you for the new draft. A few comments: - Please mention the question of IKE keepalive

Re: [IPsec] New Version Notification for draft-nir-ipsecme-ike-tcp-00.txt

2012-06-14 Thread John Leser
On 06/14/12 16:25, Yoav Nir wrote: On Jun 14, 2012, at 10:34 PM, John Leser wrote: On 06/14/12 13:39, Yoav Nir wrote: Hi Yaron Responses are inline. Yoav On Jun 14, 2012, at 1:40 AM, Yaron Sheffer wrote: Hi Yoav, thank you for the new draft. A few comments: - Please mention the