[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

ICMP errors to IPSECed data?



Just noticed, is the chapter 6 in RFC-2401 actually indicating that
following should happen?

> - should ICMP error messages actually get the security from a policy
>   that matches the returned packet they are trying to report?
>   [e.g. instead of matching ICMP to the selectors, match the
>   contained packet instead (feels a bit complex and kludgy)]

-- 
Markku Savela (msa@hemuli.tte.vtt.fi), Technical Research Centre of Finland
Multimedia Systems, P.O.Box 1203,FIN-02044 VTT,http://www.vtt.fi/tte/staff/msa/