Re: [IPsec] Can one IPsec SA be established via two internet ports on one device?

2018-11-19 Thread Paul Wouters
On Mon, 19 Nov 2018, Linda Dunbar wrote: When you said “IPs are sourced loopbacks that are part of a prefix exported to the the isp(s) in each site”, do you mean that the private Loopback addresses of CPE1 & CPE2 are routable in all four  ISPs’ that connected to A1, A2, B1, B2? And to

Re: [IPsec] Can one IPsec SA be established via two internet ports on one device?

2018-11-19 Thread Linda Dunbar
ggli [mailto:joe...@gmail.com] Sent: Monday, November 19, 2018 2:18 PM To: Linda Dunbar Cc: IPsecME WG Subject: Re: [IPsec] Can one IPsec SA be established via two internet ports on one device? On Nov 19, 2018, at 11:19, Linda Dunbar mailto:linda.dun...@huawei.com>> wrote: IPs

[IPsec] Can one IPsec SA be established via two internet ports on one device?

2018-11-19 Thread Linda Dunbar
IPsec experts, In the following diagram, CPE1 has two internet ports, A1 by one service provider, A2 by another service provider. CPE2 also have two ports facing two different internet service providers Question: can I establish ONE IPsec SA between CPE1 & CPE2? (i.e. between 10.1.1.1 &