I'm concerned about the direction of the connection. The current spec implies that the device only expects inbound connections - section 1.1 states that device==server and app==client; and section 2.1 doesn't clarify.
I believe that the device should be able to initiate the connection to the app (i.e. an NMS) as it:
1) enables the manageability of devices behind a Port NAT 2) enables the device to manage failover (when NMS can't) 3) enables the device to not have an open port (for stealth mode)
Has this already been considered? - I didn't see anything in the mailing list archive...
Kent
--
Kent Watsen Software Architect NetScreen Technologies, Inc. kwatsen@netscreen.com (W) 408.543.4027 (C) 650.722.3315
|