[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Replay problem



In message <714BE32F82EED211B9CA0008C7C5A4DA0313D872@zuk28exm01.ecid.cig.mot.co
m>, Shi Rong-rongshi1 writes:
>Dear Steve,
>
>I noticed the discussion last year about loosing anti-replay protection in
>IPsec in case of manually SA management. Are there any changes in
>specificationsince then to address the issue of preserving anti-replay
>protection while using manaul SA mgmt?
>
>Regards,
>
>Rong
>
No.  The problem is that if a machine loses state (say, due to a 
reboot), it would restart the sequence space, allowing replays.  
There's also the issue of how to handle wrap-around.

		--Steve Bellovin