Re: [Full-disclosure] IPv6 security myths

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



>>>>> "Masataka" == Masataka Ohta <mohta@xxxxxxxxxxxxxxxxxxxxxxxxxx> writes:
    Masataka> My context is IPsec in the Internet, which excludes VPNs.

    Masataka> Do you know some major application over the Internet using
    Masataka> IPsec with transport mode?

Why the restriction of *over*?
Dozens of IETF specifications are not used *over* the Internet, but only
over IP.  Recall that the IETF is about standardizing things over IP,
the internet is only a (large) subset of that.

iSCSI specifies IPsec in transport mode.
L2TP specifies IPsec in transport mode (but, that's remote-access, which
usually means VPNs, so you want exclude that).

So you are right: IPsec in transport mode is rarely used by popular
protocols.  But, it is out there, often being used to secure
applications that are one-offs, or whose use is not well known. 

That was the point of IPsec: It's a layer of security for people to use
rather than invent their own.

-- 
]       He who is tired of Weird Al is tired of life!           |  firewalls  [
]   Michael Richardson, Sandelman Software Works, Ottawa, ON    |net architect[
] mcr@xxxxxxxxxxxxxxxxxxxxxx http://www.sandelman.ottawa.on.ca/ |device driver[
   Kyoto Plus: watch the video <http://www.youtube.com/watch?v=kzx1ycLXQSE>
	               then sign the petition. 
_______________________________________________
Ietf mailing list
Ietf@xxxxxxxx
https://www.ietf.org/mailman/listinfo/ietf


[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Fedora Users]