Re: [IPsec] Call for agenda items

2012-10-17 Thread Yaron Sheffer
A quick correction: the latest version of the now-finished draft has been renamed draft-ietf-ipsecme-ad-vpn-problem (auto-discovery VPN, http://tools.ietf.org/html/draft-ietf-ipsecme-ad-vpn-problem-00). Thanks, Yaron On 10/17/2012 04:38 PM, Paul Hoffman wrote: Greetings again. We

Re: [IPsec] Call for agenda items

2012-10-17 Thread Paul Hoffman
On Oct 17, 2012, at 7:52 AM, Yaron Sheffer yaronf.i...@gmail.com wrote: A quick correction: the latest version of the now-finished draft has been renamed draft-ietf-ipsecme-ad-vpn-problem (auto-discovery VPN, http://tools.ietf.org/html/draft-ietf-ipsecme-ad-vpn-problem-00). Whoops, yes. An

Re: [IPsec] Call for agenda items

2012-10-17 Thread Yoav Nir
On Oct 17, 2012, at 4:38 PM, Paul Hoffman wrote: Greetings again. We have a 2-hour time slot in Atlanta, which is way more than we asked for. We don't need to be talking about draft-ietf-ipsecme-p2p-vpn-problem because it's finished with WG LC and is being sent to the AD for review. Are

Re: [IPsec] STRONG NUDGE: Revised AD VPN Requirements

2012-10-17 Thread Vishwas Manral
Hi Chris, Thanks a lot for your comments, my points inline: On Wed, Oct 17, 2012 at 7:47 AM, Ulliott, Chris chris.ulli...@cesg.gsi.gov.uk wrote: Apologies for the delay in replying... I think the Gateway to gateway use case (para 2.2) doesn't cover the problem I'm suffering. What if the

Re: [IPsec] New I-D on IKEv3

2012-10-17 Thread David Brownhill (dbrownhi)
Hi Dan, The lack or EAP authentication would be a non-starter for us to implement this in our remote access VPN client. Why not support EAP authentication? Regards, David -Original Message- From: ipsec-boun...@ietf.org [mailto:ipsec-boun...@ietf.org] On Behalf Of Dan Harkins Sent:

Re: [IPsec] New I-D on IKEv3

2012-10-17 Thread Dan Harkins
Hi David, On Wed, October 17, 2012 11:36 am, David Brownhill (dbrownhi) wrote: Hi Dan, The lack or EAP authentication would be a non-starter for us to implement this in our remote access VPN client. Why not support EAP authentication? What credential are you interested in using with

Re: [IPsec] New I-D on IKEv3

2012-10-17 Thread Dan Harkins
Hi Yoav, On Wed, October 17, 2012 11:52 am, Yoav Nir wrote: Add a CFG payload to the list. Already noted! CFG and NAT indication. By the time we add all the things that we feel must be in an IKEv3, would it be any simpler than IKEv2? Yes, I believe so. Simpler, more clear, and easier

Re: [IPsec] Call for agenda items

2012-10-17 Thread Dan Harkins
On Wed, October 17, 2012 7:38 am, Paul Hoffman wrote: Greetings again. We have a 2-hour time slot in Atlanta, which is way more than we asked for. We don't need to be talking about draft-ietf-ipsecme-p2p-vpn-problem because it's finished with WG LC and is being sent to the AD for review. This