[IPsec] Meetecho support for IPSECME session

2013-03-11 Thread Meetecho Team
Dear all, a virtual room has been reserved on the Meetecho system for the IPSEC WG meeting session. Access to the on-line session (including audio and video streams) will be made available (just a couple of minutes before session start time) at: http://www.meetecho.com/ietf86/ipsecme The

Re: [IPsec] draft-yamaya-ipsecme-mpsa-00

2013-03-11 Thread Praveen Sathyanarayan
If I understood accurately, author meant to establish mesh BGP sessions, which would allow discovery of each other information. But IMO, this may cause scale issue. AD-VPN is mainly to address a large VPN deployments. As an example, say 2000 end-points are deployed. With this MESH approach, there a

Re: [IPsec] draft-yamaya-ipsecme-mpsa-00

2013-03-11 Thread Paul Wouters
Regarding draft-yamaya-ipsecme-mpsa-00 The draft claims to be about "auto discovery and configuration function". However, I don't actually see any of that in the draft. I have no idea how nodes find out about other nodes they can talk IPsec to. What I do see in the draft is a mechanism for a g

Re: [IPsec] draft-smyslov-ipsecme-ikev2-fragmentation-00 fragmentation size question

2013-03-11 Thread Valery Smyslov
Hi, Paul, thank you for reading the draft. I have a question about http://tools.ietf.org/html/draft-smyslov-ipsecme-ikev2-fragmentation-00#section-2.5.1 It states: 2.5.1. Fragment size When breaking content of Encrypted Payload down into parts sender SHOULD chose size of those parts

Re: [IPsec] draft-smyslov-ipsecme-ikev2-fragmentation-00 fragmentation size question

2013-03-11 Thread Paul Wouters
On Mon, 11 Mar 2013, Valery Smyslov wrote: I have a question about http://tools.ietf.org/html/draft-smyslov-ipsecme-ikev2-fragmentation-00#section-2.5.1 It states: 2.5.1. Fragment size What is "message size" here referring to? The fragmentation payload, or the total packet length? That is