Hello every one
im new to vpp ipsec and i saw there has been an improvment in version vpp 19.01 
for ipsec.

i have a couple of questions regarding ipsec on vpp.

1. after that i have new port name lets say "ipsec0", is there a unique 
identifier that will show from what *ikev2 profile it has been created* ? (if i 
have many connections i want to know which one is which for status and 
statistics...)

2. can i use multiple isakmp policies (ans esp also )for a *single ikev2 
profile*  in vpp ( ikev2 profile set pr1 ike-crypto-alg  ike-integ-alg  ike-dh 
)??
for a eample in strongswan:
conn %default
        keyexchange=ikev2
        authby=secret
        type=tunnel
       *ike=aes256-sha2_512-modp2048,aes128-sha1-ecp384,aes128-sha1-modp1536!*
        dpdaction=clear
        dpddelay=3
        dpdtimeout=15
        mobike=no

if so how is the best practive - i dont think using 3 diff profiles with just 
diffrent ike profiles will do the trick becouse i can end up with multipule 
connections that i didnt wanted...

thanks in advance!!!
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#12484): https://lists.fd.io/g/vpp-dev/message/12484
Mute This Topic: https://lists.fd.io/mt/30389253/21656
Group Owner: vpp-dev+ow...@lists.fd.io
Unsubscribe: https://lists.fd.io/g/vpp-dev/unsub  [arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to