[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Internet Draft -- IPsec Architecture
3rd paragraph in 4.1:
As noted above, two types of SAs are defined: transport mode and
tunnel mode. A transport mode SA is a security association between
two hosts. The security protocol header appears immediately after
the IP header (and any options or extensions), and before any higher
layer protocols (e.g., TCP or UDP). In the case of ESP, a tunnel
^^^^^^
Isn't this transport?
mode SA provides security services only for these higher layer
protocols, not for the IP header. In the case of AH, the protection
is also extended to selected portions of the IP header (and options).
For more details on the coverage afforded by AH, see the AH
specification [KA97b].
Robert Moskowitz
Chrysler Corporation
(810) 758-8212
Follow-Ups: