[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [BEHAVE] Re: CPE equipments and stateful filters



On Jul 30, 2007, at 23:43, Dan Wing wrote:

...or the server would need to tell its firewall to permit unsolicited incoming traffic.

It would be more accurate to describe that method like this: the server would need to solicit the firewall to permit 1) inbound IKE initiations from arbitrary remote addresses, and 2) IPsec ESP/AH flows for negotiated security associations. Neither of these two forms of traffic could reasonably be described as "unsolicited" in this case.


--
james woodyatt <jhw@apple.com>
member of technical staff, communications engineering