[Sis-csi] IPSec AH and SCPS-NP
Marc Blanchet
marc.blanchet at viagenie.ca
Thu Dec 7 09:43:08 EST 2006
Maybe my comment is dumb, but why don't tunnel IPv*-with-IPsec into
the payload of SCPS-NP (i.e. include the whole IP header and payload
into the payload of SCPS-NP) and then you have "nothing" to do to
support IPsec in NP, since IPsec will be managed by IP devices. dumb?
Marc.
Le 06-12-06 à 15:28, Scott, Keith L. a écrit :
> As part of our charter item to update existing CCSDS
> specifications, there is a rather old outstanding action item to
> update the SCPS Network Protocol (SCPS-NP) to support carriage of
> information needed for end-to-end IPSec AH across SCPS-NP networks.
>
> I put together some slides on this topic and placed them at (http://
> public.ccsds.org/sites/cwe/sis-csi/Public/Draft%20Documents/Carrying
> %20IPSEC%20Authentication%20Headers%20in%20SCPS-NP.ppt). The
> slides present three options with varying implications (one option
> uses only a new TPID but costs a byte, the other two have lower
> overhead but use bits from the NP control field).
>
> I'd like to open this up for disucussion and try to come to a rough
> consensus before we go into the January meetings.
>
> --keith
>
> _______________________________________________
> Sis-CSI mailing list
> Sis-CSI at mailman.ccsds.org
> http://mailman.ccsds.org/cgi-bin/mailman/listinfo/sis-csi
More information about the Sis-CSI
mailing list