[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: IBM VPN Bakeoff Issues



> Yes, a point that was not raised at the workshop.  We did a 
> test with AH+ESP
> in tunnel mode. We took this to mean AH+ESP adjacent with a 
> shared tunnel
> header.  The other vendor took this to mean 
> IP1+AH+IP2+ESP+IP3.  There was
> some agreement that a proposal that offered AH-tunnel AND 
> ESP-tunnel should
> mean a shared tunnel-header, but maybe we need more text somewhere.

Maybe I'm not understanding this. Looking at the four possible combinations,
this is my understanding of how transport & tunnel mode combine:

AH-transport + ESP-transport:
	IP1 AH ESP transport
AH-transport + ESP-tunnel:
	IP1 AH ESP IP2 transport
AH-tunnel + ESP-transport:
	IP1 AH IP2 ESP transport
AH-tunnel + ESP-tunnel:
	IP1 AH IP2 ESP IP3 transport

Rich