[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [BEHAVE] Re: CPE equipments and stateful filters
On Jul 30, 2007, at 23:43, Dan Wing wrote:
...or the server would need to tell its firewall to permit
unsolicited incoming traffic.
It would be more accurate to describe that method like this: the
server would need to solicit the firewall to permit 1) inbound IKE
initiations from arbitrary remote addresses, and 2) IPsec ESP/AH
flows for negotiated security associations. Neither of these two
forms of traffic could reasonably be described as "unsolicited" in
this case.
--
james woodyatt <jhw@apple.com>
member of technical staff, communications engineering