[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: AH & IPv4 options
Routers that arbitrarily reorder IP options are broken.
Bill Simpson "educated" me about this issue offline. To the best of
my knowledge (including my understanding of Bill's inputs) those
routers never included high-volume vendors (e.g. Cisco, Wellfleet/Bay,
3COM) and the software releases that did reorder options are ancient
by now. To the best of my understanding, all such routers were
derived in part on a single original TCP/IP stack. That original
stack has not reordered options for a long while now. I don't think we
can or should make any effort to protect AH from such routers. I don't
think we should change specs just to make older broken systems
conforming.
What of routers -- specifically Cisco -- that will add or delete IPSO
options? Bill claimed that that's broken, too -- but it certainly exists,
and is probably necessary for single-level systems on, say, top secret
nets.
Follow-Ups: