But that seems like more of an argument against IKE than IPsec.
I don't see anything wrong with IKEv2. The problem isn't the KE, theproblem, and neither is ESP.The problem is the architecture, and the parts of it relating toauthorization that get implemented by the KE (or related service).
Ahh - thanks.
Just wanted to know what we need to eventually fix…
Joe
|