[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: draft-ietf-v6ops-cpe-simple-security: filtering encapsulated flows
On Aug 22, 2009, at 21:58, Truman Boyes wrote:
This is quite confusing from an implementation perspective; security
is not explicitly increased by prohibiting non-encrypted tunnels but
allowing encrypted (ESP or AH) traffic flows. Wouldn't this simply
serve as a driver to make all tunnel encapsulations use ESP/AH?
Yes. I'm not sure I can explain how this is supposed to increase
security, but if consensus in the working group emerges around these
recommendations and the draft can proceed through working group last
call, then that's good enough for me.
--
james woodyatt <jhw@apple.com>
member of technical staff, communications engineering