Re: [IPsec] IKE6 Negitaion when Peer Address ND not yet started.

2010-02-23 Thread Yoav Nir
On Feb 22, 2010, at 5:48 PM, Stephen Kent wrote: > At 7:22 PM +0530 2/22/10, Syed Ajim Hussain wrote: >> Hi Steve >>According to me IPSEC/IKE should have intelligence by by-pass ND Traffic >> >>when SA is not ready state without end-user intervention, and same >>should be accepted by

Re: [IPsec] IKE6 Negitaion when Peer Address ND not yet started.

2010-02-23 Thread Stephen Kent
Yoav, I did not mean to suggest that the SPD UI has to be a low level interface that makes it difficult for users to achieve their secruity goals. On the other hand, I would be surprised if any vendor's UI really accepted English (or another human communication language). So, despite the fac

[IPsec] FYI: NIST Publication "Guidelines for the secure deployment of IPv6"

2010-02-23 Thread Ed Jankiewicz
I had nothing to do with this doc, and have not fully reviewed it yet, but thought it would be of interest to folks on these lists. Please do not send your comments to me or post on these lists, but follow the instructions at the link to comment directly to the authors. I am sure NIST would a