[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: IBM VPN Bakeoff Issues
> Yes, a point that was not raised at the workshop. We did a
> test with AH+ESP
> in tunnel mode. We took this to mean AH+ESP adjacent with a
> shared tunnel
> header. The other vendor took this to mean
> IP1+AH+IP2+ESP+IP3. There was
> some agreement that a proposal that offered AH-tunnel AND
> ESP-tunnel should
> mean a shared tunnel-header, but maybe we need more text somewhere.
Maybe I'm not understanding this. Looking at the four possible combinations,
this is my understanding of how transport & tunnel mode combine:
AH-transport + ESP-transport:
IP1 AH ESP transport
AH-transport + ESP-tunnel:
IP1 AH ESP IP2 transport
AH-tunnel + ESP-transport:
IP1 AH IP2 ESP transport
AH-tunnel + ESP-tunnel:
IP1 AH IP2 ESP IP3 transport
Rich