[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Q: What is advantage of tunnel mode between host to host scenrio?



On Thu, 23 Mar 2000, rupesh wrote:
> With Ref to RFC2401 tunnel mode between host to host MUST be supported
> without any Gateway in picture.In such a condition my Outer IP header will
> be same as Inner IP header.I am unable to visualise advantage of such a
> Mode...

The outer IP header won't be *exactly* the same as the inner one.  In
particular, the higher-level protocol identifier will be hidden.

Also, the fact that the outer and inner IP headers are similar is not
obvious to an eavesdropper.  If the gateways are (or could be) also
carrying IPSec traffic on behalf of other sites, there is considerable
added security in this. 

                                                          Henry Spencer
                                                       henry@spsystems.net



References: