> > > >I am not sure if this is the case. For example, I believe there >is no technical problem to have some IPsec policies set up before >there is any external connectivity. In fact, one may want to do >exactly this so that the policies are enforced right from the >beginning. I'd suggest you to talk to the IPsec team for their >opinion. > > > Yep. You are right. IPsec services should have nothing to do with network. They should depend on system/cryptosvc. And this is why they file 6185380 to fix it. (Currently IPsec is not a separate service, and is enabled in network/initial because network/initial depends on system/cryptosvc)
-Jan