Re: [IPsec] IPsec profile feedback wanted (draft autonomic control plane)

2020-02-25 Thread Yoav Nir
Hi, Toerless. I trimmed below most of your background info. > On 24 Feb 2020, at 21:50, Toerless Eckert wrote: > > [hope its fine to cross-post ipsec and ipsecme given how one is concluded, > but may have > more long-time subscribers] ipsec is this group’s mailing list. I don’t know that ther

Re: [IPsec] IPsec profile feedback wanted (draft autonomic control plane)

2020-02-25 Thread Toerless Eckert
On Tue, Feb 25, 2020 at 10:17:30PM +0200, Yoav Nir wrote: > ipsec is this group???s mailing list. I don???t know that there even is an > ipse...@ietf.org Yepp. Silly me. Didn't check that ipsecme was keeping the old mailing list name. > I read a little more. Hope you do

Re: [IPsec] IPsec profile feedback wanted (draft autonomic control plane)

2020-02-25 Thread Michael Richardson
Yoav Nir wrote: > The profile specifies that the ACP nodes should use tunnel mode (when > GRE is not used), because: IPsec tunnel mode is required because the > ACP will route/forward packets received from any other ACP node across > the ACP secure channels, and not only its own g

Re: [IPsec] IPsec profile feedback wanted (draft autonomic control plane)

2020-02-25 Thread Toerless Eckert
Michael: Yoav talked about the non-GRE case. On Tue, Feb 25, 2020 at 05:44:10PM -0500, Michael Richardson wrote: > > Yoav Nir wrote: > > The profile specifies that the ACP nodes should use tunnel mode (when > > GRE is not used), because: IPsec tunnel mode is required because the > >

Re: [IPsec] IPsec profile feedback wanted (draft autonomic control plane)

2020-02-25 Thread Michael Richardson
> Michael: Yoav talked about the non-GRE case. In the non-GRE case, then it's just IPIP-over-IPSEC-transport mode. Which is literally the VTI case. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT a

Re: [IPsec] IPsec profile feedback wanted (draft autonomic control plane)

2020-02-25 Thread Yoav Nir
The draft says “IPsec tunnel mode is required ”, so it’s not transport. What goes in the TS payloads? > On 26 Feb 2020, at 3:20, Michael Richardson wrote: > > >> Michael: Yoav talked about the non-GRE case. > > In the non-GRE case, then it's just IPIP-over-IPSEC-transport mode. > Which is lit