[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: mixed mode datagrams



Hilarie,

>Is it the intention of the specifications to allow an IP datagram to
>be reassembled from a combination of ESP-protected fragments tunnelled
>through different security associations (including the possibility
>of no ESP protection)?

ESP operates on fragments if the fragments arrive at a security gateway and
are then encapsulated in ESP. Thus it is possible for fragments to arrive
at multiple SGs outbound and be passed on multiple SAs, and even arrive at
multiple receiving SGs.  However, there is no requirement that these
fragments be reassembled prior to deliver to the ultimate recipient.  The
problem, as Mike points out, is that if one has SPD entries at the
destination SG(s) that want to look at port fields, this scenario will
fail.  However, contrary to what Mike suggests, implicit ordering of the
SPD would not address this problem, as my example above illustrates, in
more complex topologies.  (Mike's example also seems to make use of a range
for port values [>1024], a feature that was once present in the SPD, but
was dropped because IKE cannot negitiate it.)

Steve


References: