[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

VPN Touch doc




3.3 Solving Problem 2: Source Address Selection


   Section 2.4 gave an overview of IP source address selection and its
   dependence on interfaces and routes.

   Using RFC 2003 IPIP tunnel devices for VN links, instead of IPsec
   tunnel mode SAs, solves this issue directly. The IPIP tunnels are
   full-fledged interfaces with associated routes, so that routes [N4]
   and address selection as described in [N6] can operate as specified.



*****>>>This doesn't seem to be an adequate treatment of the problem.  In
general, the host may still have to select among multiple possible source
addresses; is this trying to say that by specifying a system in which
the tunnels are interfaces the problem collapses from source selection
to interface selection?  If so, a more fully worked example of why this
works for the examples given seems like it would be useful.