[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Replay problem
In message <714BE32F82EED211B9CA0008C7C5A4DA0313D872@zuk28exm01.ecid.cig.mot.co
m>, Shi Rong-rongshi1 writes:
>Dear Steve,
>
>I noticed the discussion last year about loosing anti-replay protection in
>IPsec in case of manually SA management. Are there any changes in
>specificationsince then to address the issue of preserving anti-replay
>protection while using manaul SA mgmt?
>
>Regards,
>
>Rong
>
No. The problem is that if a machine loses state (say, due to a
reboot), it would restart the sequence space, allowing replays.
There's also the issue of how to handle wrap-around.
--Steve Bellovin