[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ICMP Security Failures



In message <9512271952.AA19612@uncial.CS.Arizona.EDU>, Hilarie Orman writes:
>Some combinations may not be possible, due to ambiguities in
>processing order.  For example, IP-AH-AH or IP-ESP-AH.

	I think IP-AH-AH is valid, though maybe not very useful. You
would process those in order, i.e., the first AH would cover the payload,
and the second AH would cover the first AH and the payload.

	I don't think IP-ESP-AH is valid -- it would have to be IP-ESP-IP-AH.

									-Craig


Follow-Ups: References: