Re: [IPsec] Potential way forward for IPsecME on ESP-NULL

2009-03-05 Thread Gregory Lebovitz
I support this approach to moving forward. - Gregory -- IETF related email from Gregory M. Lebovitz Juniper Networks On Wed, Feb 18, 2009 at 8:05 AM, Grewal, Ken wrote: > Hi Paul, > I have no objections to this approach moving forward. > > Thanks, > - Ken > > > >-Original Message-

Re: [IPsec] WESP - Roadmap Ahead

2009-11-17 Thread Gregory Lebovitz
inline... On Mon, Nov 16, 2009 at 8:18 AM, Stephen Kent wrote: > At 7:50 PM +0530 11/16/09, Bhatia, Manav (Manav) wrote: > >> This is an implementation specific optimization that has already been >> solved in multiple implementations. >> >> Cheers, Manav >> > > Is the phrase "implementation spec

Re: [IPsec] WESP - Roadmap Ahead

2009-11-17 Thread Gregory Lebovitz
inline... On Mon, Nov 16, 2009 at 8:39 AM, Stephen Kent wrote: --snip-- > I am not suggesting that any aspect of your analysis is flawed. I am > suggesting that before the WG chooses to further deprecate AH, it needs to > document the analysis supporting this decision, not just cite a couple o

Re: [IPsec] How long does an IKEv1 session take to complete?

2009-11-18 Thread Gregory Lebovitz
Additionally it will depend on the round trip time across the network between the two peers. Vendors who are selling network boxes that can do a large number of simultaneous IKE negotiations tend to care more about simultaneous IKE SA negotiations per second than they do the actual negotiation tim