Paul, I understand that there are folks who want to count packets. However, the _purpose_ of using IPsec is to make it difficult for an adversary to know what is going on. If a user has turned on IPsec for his traffic, its because the user does not want this information in the clear, else the user would have used upper-layer security services instead of IPsec. Ran rja@cisco.com