Re: [IPsec] your example (like Gap) about IPSec VPN gateway deployed in shopping mall not aware of where the controller is.

2017-09-13 Thread Mike Sullenberger (mls)
ttp://www.ciscolive.com/> Mike SullenbergerCCIE-2902 m...@cisco.com<mailto:m...@cisco.com> Tel: +1 408 527 8702 Cisco.com DISTINGUISHED ENGINEER. ENGINEERING Product Development Cisco Systems, Inc. [http://www.cisco.com/assets/swa/img/thinkbeforeyouprint.gif] Think befo

Re: [IPsec] DMVPN thoughts

2013-11-26 Thread Mike Sullenberger (mls)
Timo, Comments Inline. Mike. Mike Sullenberger, DSE m...@cisco.com    .:|:.:|:. Customer Advocacy  CISCO -Original Message- From: Timo Teräs [mailto:timo.te...@gmail.com] On Behalf Of Timo Teras Sent: Monday, November 25, 2013 10:30 PM To: Mike Sullenberger (mls

Re: [IPsec] DMVPN thoughts

2013-11-25 Thread Mike Sullenberger (mls)
Timo, Thank you very much for your comments. I had not realized that anyone had tried to implement our additions to NHRP, it is nice to hear that it wasn't too hard to do. I have a couple of comments, inline. Mike. Mike Sullenberger, DSE m...@cisco.com    .:|:.:|:. Customer Advocacy

Re: [IPsec] AD VPN: discussion kick off

2013-11-05 Thread Mike Sullenberger (mls)
] Mike Sullenberger, DSE m...@cisco.com.:|:.:|:. Customer Advocacy CISCO From: Stephen Kent [mailto:k...@bbn.com] Sent: Monday, November 04, 2013 1:57 PM To: Mike Sullenberger (mls); Michael Richardson Cc: Stephen Lynn (stlynn); draft-detienne-dm...@tools.ietf.org; Mark

Re: [IPsec] AD VPN: discussion kick off

2013-11-04 Thread Mike Sullenberger (mls)
they will have to all keep their databases in sync, which adds more problems when trying to scale these networks to 10s of thousands of nodes and larger. Mike. Mike Sullenberger, DSE m...@cisco.commailto:m...@cisco.com.:|:.:|:. Customer Advocacy CISCO -Original Message

Re: [IPsec] Some comments on draft-detienne-dmvpn-00

2013-10-28 Thread Mike Sullenberger (mls)
Lou, Thanks, again answer inline :-). Mike. Mike Sullenberger, DSE m...@cisco.com    .:|:.:|:. Customer Advocacy  CISCO -Original Message- From: Lou Berger [mailto:lber...@labn.net] Sent: Thursday, October 24, 2013 8:57 AM To: Mike Sullenberger (mls) Cc: IPsecme

Re: [IPsec] Some comments on draft-detienne-dmvpn-00

2013-10-23 Thread Mike Sullenberger (mls)
Lou, Thank you for your comments, more inline. Mike. Mike Sullenberger, DSE m...@cisco.com    .:|:.:|:. Customer Advocacy  CISCO -Original Message- From: Lou Berger [mailto:lber...@labn.net] Sent: Friday, October 18, 2013 3:29 PM To: draft-detienne-dm

Re: [IPsec] I-D Action: draft-ietf-ipsecme-ikev2-fragmentation-03.txt

2013-10-17 Thread Mike Sullenberger (mls)
As I remember it IPv4 has a minimum packet size of 576 that won't (or at least shouldn't be) fragmented by IP. Mike. Mike Sullenberger, DSE m...@cisco.com    .:|:.:|:. Customer Advocacy  CISCO -Original Message- From: ipsec-boun...@ietf.org [mailto:ipsec-boun

Re: [IPsec] I-D Action: draft-ietf-ipsecme-ikev2-fragmentation-03.txt

2013-10-17 Thread Mike Sullenberger (mls)
Yoav, Yes, I agree. In fact except for tunneling stealing bytes, you could likely get away with 1500 bytes. I think that 1280 is good compromise, with perhaps a hop down to 576 if 1280 runs into trouble. Mike. Mike Sullenberger, DSE m...@cisco.com    .:|:.:|:. Customer Advocacy

Re: [IPsec] Does ESP provide all functionality offered by AH?

2011-11-16 Thread Mike Sullenberger
. ++ | Mike Sullenberger; DSE | | m...@cisco.com.:|:.:|:. | | Customer Advocacy CISCO | ++ ___ IPsec mailing list

Re: [IPsec] P2P VPN - Side Meeting

2011-11-15 Thread Mike Sullenberger
a new never-before-published solution that's fine as well, but I have no such intentions. Yoav ___ IPsec mailing list IPsec@ietf.org https://www.ietf.org/mailman/listinfo/ipsec ++ | Mike Sullenberger; DSE

Re: [IPsec] P2P VPN - Side Meeting

2011-11-15 Thread Mike Sullenberger
Mike == Mike Sullenberger m...@cisco.com writes: Mike We use other tunnel mechanisms (GRE), because IPsec tunneling mode Mike is lacking in functionality. For example, when you use GRE for the Mike tunneling you also reduce the IPsec SA's that are needed to Mike describe

Re: [IPsec] New -00 draft: Creating Large Scale Mesh VPNs Problem

2011-11-11 Thread Mike Sullenberger
. ___ IPsec mailing list IPsec@ietf.org https://www.ietf.org/mailman/listinfo/ipsec ___ IPsec mailing list IPsec@ietf.org https://www.ietf.org/mailman/listinfo/ipsec ++ | Mike

Re: [IPsec] New -00 draft: Creating Large Scale Mesh VPNs Problem

2011-11-10 Thread Mike Sullenberger
that some of us had previously discussed. -geoff ___ ++ | Mike Sullenberger; DSE | | m...@cisco.com.:|:.:|:. | | Customer Advocacy CISCO