[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: ESP and AH used in tunnel mode by a Security Gateway



Steve,

>	Yes, I suppose once I have applied ESP-Tunnel, using AH as well
>become transport mode - unless
>	I really want to incur the overhead of yet another IP header.

See my note to Ben.  If an SA originates or termninates at an SG, it MUST
be in tunnel mode.  We've been over this several time before.

Steve




References: