[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: RFC 2401 section 5.2.1
"Joseph D. Harwood" wrote:
>
> >
> > What does tunnel mode give you that IPIP tunnels + IPsec transport mode
> > don't? Inbound processing for both should be identical, since you can't
> > tell the difference by looking at the packet.
>
> Not quite identical. After IPsec processing, the received packet's
> selectors are checked against the SPD to make sure all of the appropriate
> processing has been performed. In Tunnel mode, these selectors are from the
> inner (encapsulated) header, in IPIP + IPsec transport these selectors are
> from the outer header.
Agreed. It's exactly that difference that allows IPIP+transport
to support dynamic routing over per-hop IPSEC'd tunnels.
Joe
References: