Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101])
 by above.proper.com (8.11.6/8.11.3) with ESMTP id g24Mtr815821;
 Mon, 4 Mar 2002 14:55:53 -0800 (PST)
Received: by lists.tislabs.com (8.9.1/8.9.1) id RAA26889
 Mon, 4 Mar 2002 17:22:15 -0500 (EST)
Date: Mon, 4 Mar 2002 14:32:48 -0800 (PST)
From: Srinivasa Addepalli <srao@intotoinc.com>
To: "Chinna N.R. Pellacuru" <pcn@cisco.com>
cc: Jayant Shukla <jshukla@trlokom.com>,
 "'Henrik Levkowetz'" <henrik@ipunplugged.com>,
 "'ipsec mailling list'" <ipsec@lists.tislabs.com>
Subject: RE: NAT Traversal
In-Reply-To: <Pine.GSO.4.33.0203041230280.23950-100000@cypher.cisco.com>
Message-ID: <Pine.LNX.4.21.0203041429360.1922-100000@intotoinc.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

On Mon, 4 Mar 2002, Chinna N.R. Pellacuru wrote:

> On Mon, 4 Mar 2002, Srinivasa Addepalli wrote:
> >   Also think of Manual Key Managed IPSEC policies. SPIs are manually
> >   configured.
> >
> 
> And, why can't manually configured SPIs follow the new semantics?
> 
>     chinna

Both IKE and manual key management exist on the same 
device. Typically, to make the management and configuration easy,
devices restrict the SPIs to be in some range for MKM policies, so
that there will not be any conflict on SPIs chosen for IKE based
SPD policies and MKM based SPD policies. Though this is not
a strong argument, it might make configuration difficult.
> 

-- 
Srinivasa Rao Addepalli
Intoto Inc.
3160, De La Cruz Blvd #100
Santa Clara, CA
USA
Ph: 408-844-0480 x317

