[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
ICMP and TCP
>>>>> "Michael" == Michael Richardson <mcr@sandelman.ottawa.on.ca> missed
some words, confusing his meaning:
Michael> Assume a TCP connection that traverses a network, and is carried
Michael> with IPsec (perhaps just AH) in "transport" mode. If there is
Michael> some reason to believe that AH (or ESP) is on that network path,
...if there is some reason to believe that AH/ESP is needed on that network
path, that is if you believe that there may be an eavesdropper or active
TCP spoofer, then I would suggest that there is sufficient additional reason
to worry that they will simply destructive shut you down with ICMP, or
perhaps even just ICMP ping floods
:!mcr!: | Sandelman Software Works Corporation, Ottawa, ON
Michael Richardson | SSH IPsec: http://www.ssh.fi/. Secure, strong, international
Personal: <A HREF="http://www.sandelman.ottawa.on.ca/People/Michael_Richardson/Bio.html">mcr@sandelman.ottawa.on.ca</A>. PGP key available.
Corporate: <A HREF="http://www.sandelman.ottawa.on.ca/SSW/">sales@sandelman.ottawa.on.ca</A>.
References: