On Nov 7, 2013, at 9:43 AM, Tero Kivinen <[email protected]>
 wrote:

> Yoav Nir writes:
>> The VPN products from Cisco, Juniper and Check Point support them,
>> as well as both StrongSwan and OpenSwan. I'm sure there are others
>> as well. 
> 
> But which version of their products support which version of the ECC
> groups? For example I have no idea which version our toolkit, our
> customers are using in their products, so I cannot know which version
> of groups they support. I do know that some of them do use very old
> versions, because there release cycle is very long.

I'm pretty sure that is true for my company's customers as well.

> So have you actually seen anyone actually using those groups between
> different vendors?

Perhaps we should have an interop event. How about the Sunday of the London 
meeting?

> I think quite a lot of our customers still have
> IKEv1 configured by default, and they have not yet moved to IKEv2
> unless they want to use EAP or MOBIKE or something like that which is
> only supported by IKEv2.

I know our default is IKEv1 and I don't think many of our customers switched to 
IKEv2. Perhaps now they will, because we only support IPv6 with IKEv2.

Yoav


_______________________________________________
IPsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to