
|
Basic approach: “initiator decides” Responder sends its list of addresses to the initiator Initiator decides which pair is used for IPsec SAs and tells the responder If there is any reason to change the path (e.g., new interface, DPD failing, etc.) initiator handles it NAT Traversal can be enabled or disabled when changing path |