Re: [IPsec] Question about TS construction on IKEv2 initiator

2011-01-10 Thread Yoav Nir
Hi Gaurav There's a 1-octet field called "Number of TSs", so there can be at most 255 traffic selectors for each of initiator and responder. And yes, as many selectors are allowed as you need to describe your policy. In practice, some implementations can't handle complex policies, and require

[IPsec] Question about TS construction on IKEv2 initiator

2011-01-10 Thread Gaurav Poothia
Excerpt from RFC 5996 Sec 2.9 "To enable the responder to choose the appropriate range in this case, if the initiator has requested the SA due to a data packet, the initiator SHOULD include as the first Traffic Selector in each of TSi and TSr a very specific Traffic Selector including the