[Ipsec] traffic selector with protocol = opaque in IKEv2
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Ipsec] traffic selector with protocol = opaque in IKEv2
James Huang writes:
> In rfc2401bis, the protocol field in a SAD entry or a SPD entry may
> be opaque. However, the latest ikev2 draft does not specify how to
> represent opaque as the value for the protocol field in the traffic
> selector. Am I missing something?
>From draft-ietf-ipsec-ikev2-17.txt:
3.13.1 Traffic Selector
...
Systems that are complying with [RFC2401bis] that wish to indicate
"ANY" ports MUST set the start port to 0 and the end port to 65535;
note that according to [RFC2401bis], "ANY" includes "OPAQUE".
Systems working with [RFC2401bis] that wish to indicate "OPAQUE"
ports, but not "ANY" ports, MUST set the start port to 65535 and
the end port to 0.
--
kivinen at safenet-inc.com
_______________________________________________
Ipsec mailing list
Ipsec at ietf.org
https://www1.ietf.org/mailman/listinfo/ipsec
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.