ietf
[Top] [All Lists]

Re: [Full-disclosure] IPv6 security myths

2010-11-01 09:15:23

"Masataka" == Masataka Ohta 
<mohta(_at_)necom830(_dot_)hpcl(_dot_)titech(_dot_)ac(_dot_)jp> writes:
    Masataka> My context is IPsec in the Internet, which excludes VPNs.

    Masataka> Do you know some major application over the Internet using
    Masataka> IPsec with transport mode?

Why the restriction of *over*?
Dozens of IETF specifications are not used *over* the Internet, but only
over IP.  Recall that the IETF is about standardizing things over IP,
the internet is only a (large) subset of that.

iSCSI specifies IPsec in transport mode.
L2TP specifies IPsec in transport mode (but, that's remote-access, which
usually means VPNs, so you want exclude that).

So you are right: IPsec in transport mode is rarely used by popular
protocols.  But, it is out there, often being used to secure
applications that are one-offs, or whose use is not well known. 

That was the point of IPsec: It's a layer of security for people to use
rather than invent their own.

-- 
]       He who is tired of Weird Al is tired of life!           |  firewalls  [
]   Michael Richardson, Sandelman Software Works, Ottawa, ON    |net architect[
] mcr(_at_)sandelman(_dot_)ottawa(_dot_)on(_dot_)ca 
http://www.sandelman.ottawa.on.ca/ |device driver[
   Kyoto Plus: watch the video <http://www.youtube.com/watch?v=kzx1ycLXQSE>
                       then sign the petition. 
_______________________________________________
Ietf mailing list
Ietf(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/ietf

<Prev in Thread] Current Thread [Next in Thread>