Hi, I have posted a new version of the ikev2-ipv6-config draft (http://tools.ietf.org/id/draft-eronen-ipsec-ikev2-ipv6-config) which incorporates some new ideas based on good discussions in Vancouver (Hemant and Dave, thanks!).
In particular, Section 5 has new text discussing the most important design choices to be made, and Appendix A has additional solution sketches for several design choice combinations. Section 6 still proposes the same solution as in draft version -01; that is, point-to-point link model where prefixes are assigned in IKEv2 configuration payloads, and access control is enforced by IPsec (traffic selectors in SAD/SPD). To me this seems to be the simplest solution -- however, the additional sketches in Appendix A should make it easier to compare different alternatives; and comments about them would be especially welcome! Best regards, Pasi -------------------------------------------------------------------- IETF IPv6 working group mailing list ipv6@ietf.org Administrative Requests: http://www.ietf.org/mailman/listinfo/ipv6 --------------------------------------------------------------------