[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: draft-ietf-v6ops-cpe-simple-security: filtering encapsulated flows



On Aug 22, 2009, at 21:58, Truman Boyes wrote:

This is quite confusing from an implementation perspective; security is not explicitly increased by prohibiting non-encrypted tunnels but allowing encrypted (ESP or AH) traffic flows. Wouldn't this simply serve as a driver to make all tunnel encapsulations use ESP/AH?

Yes. I'm not sure I can explain how this is supposed to increase security, but if consensus in the working group emerges around these recommendations and the draft can proceed through working group last call, then that's good enough for me.


--
james woodyatt <jhw@apple.com>
member of technical staff, communications engineering