Re: [IPsec] Comments on draft-ietf-ipsecme-ikev2-fragmentation-00

2013-07-29 Thread Michael Richardson
Please note that fragmentation below UDP is unpopular among IPv6. http://www.ietf.org/proceedings/87/slides/slides-87-6man-2.pdf -- Michael Richardson , Sandelman Software Works pgpFULMTrmYtm.pgp Description: PGP signature ___ IPsec mailing list

[IPsec] comments on draft-sathyanarayan-ipsecme-advpn-00

2013-07-29 Thread Michael Richardson
This is a really minor comment: you reserve 3-3 as unassigned and 40K+ as private use. Why not make that boundary 49152, nice binary multiple. I also wonder if having four Shortcut Notify types might just be simpler to implement, rather than having another layer of type codes. I'm also not c

[IPsec] comments on mao-ipsecme-ad-vpn

2013-07-29 Thread Michael Richardson
Thank you for this draft. I found your writing very clear and direct. Reading the beginning of the draft, I want to suggest a change in terminology. Rather than "Private IP Address", I would to suggest that either the terms: "Protected IP address" or "Inner IP address" or "I

[IPsec] questions about ipsecme-mpsa

2013-07-29 Thread Michael Richardson
Thank your this draft. As I understand MPSA, the gateway simply generates incoming/outgoing SA pairs. I get the impression that the same information is sent to each CPE? What is this multi-point SA mentioned? Assuming that one wanted to do this, I don't see how CPE_A knows to send C's traffic