[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: IBM VPN Bakeoff Issues



> > If the discussion is really going along this line, then it has gone
> > wrong. AH transport wrapped around an ESP tunnel looks like this:
> > 
> > [IP2][AH][ESP][IP1][DATA][TLR]
> > 
> > Clearly, the AH and ESP headers are adjacent, yet the modes are
> > different, and should be declared as such in the proposal.
> 
> You mean proposal_s_.
> 
> Proposing AH&ESP to protect tunneled traffic between 2 hosts 
> is different than proposing ESP to protect tunneled traffic
> between 2 hosts (STOP, seperate negotiation) and then proposing AH to
> protect ESP traffic in transport mode between the 2 gateways.

Suppose someone in the future, for some reason we don't understand now,
wants to use AH transport wrapped around ESP tunnel, directly between two
hosts? Could this be negotiated with one proposal asking for AH-transport +
ESP-tunnel?

Rich


Follow-Ups: