[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [BEHAVE] Re: CPE equipments and stateful filters



On Jul 30, 2007, at 23:43, Dan Wing wrote:
...or the server would need to tell its firewall to permit  
unsolicited incoming traffic.
It would be more accurate to describe that method like this: the  
server would need to solicit the firewall to permit 1) inbound IKE  
initiations from arbitrary remote addresses, and 2) IPsec ESP/AH  
flows for negotiated security associations.  Neither of these two  
forms of traffic could reasonably be described as "unsolicited" in  
this case.

--
james woodyatt <jhw@apple.com>
member of technical staff, communications engineering