A further comment on Juan's point (and something that came up in
discussion after the ipdvb session, yesterday)...
If there is a security mechanism for IP (e.g. IPsec) and you want to apply
that to non-IP flows (e.g. a stream of SNDUs, Ethernet frames, ...) then
why not run the non-IP over an emulated pseudo-wire within the IPsec
tunnel? Then you only need an IP-based security solution.
I honestly don't know whether this is appropriate, but it seemed like an
interesting idea at the time!
(http://www.ietf.org/internet-drafts/draft-ietf-pwe3-iana-allocation-11.txt
already has codepoints for Ethernet, etc., but not anything specific to
the ipdvb case.)
Cheers,
Mark.
--
Mark A. West, Senior Consultant Engineer
Roke Manor Research Ltd., Romsey, Hants. SO51 0ZN
Phone +44 (0)1794 833311 Fax +44 (0)1794 833433