Folks on this list might want to take a look at a paper by David Wagner and myself: ftp://ftp.research.att.com/dist/smb/bisconf.ps. It describes an IPSEC implementation for MS-DOS. Perhaps of more interest than the paper itself are two subtle attacks on IPSEC modules, a fragmentation attack and a routing attack. --Steve Bellovin